Posted by Egidio Romano on Jul 29
——————————————————————
SugarCRM <= 14.0.0 (css/preview) LESS Code Injection Vulnerability
——————————————————————
[-] Software Link:
[-] Affected Versions:
All commercial versions before 13.0.4 and 14.0.1.
[-] Vulnerability Description:
User input passed through GET parameters to the /css/preview REST API
endpoint is not…
– Read More – Full Disclosure



