SugarCRM <= 6.3.1 Multiple PHP Object Injection Vulnerabilities


SugarCRM contains a flaw that is triggered when certain scripts fail to properly sanitize user-supplied input before being used in an unserialize() call. With a specially crafted serialized object an attacker might be able to create a cache file containing arbitrary PHP code abusing the __destruct() method of the SugarTheme class.


Disclosure Date:

June 23, 2012