RULE(RULE ID:332803)

Rule General Information
Release Date: 2021-03-26
Rule Name: SugarCRM rest_data PHP Object Deserialization Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: A script injection vulnerability exists in SugarCRM. The vulnerability is due to lack of input validation when SugarRestSerialize.php handling the rest_data parameter of a HTTP request. Remote, unauthenticated attackers could exploit this vulnerability by sending a crafted HTTP request to the target server. Successful exploitation would inject and execute PHP code on the vulnerable system.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.