SugarCRM before 10.1.0 (Q3 2020) allows SQL Injection.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17373
Reference (s):
- http://packetstormsecurity.com/files/158848/SugarCRM-SQL-Injection.html
- http://seclists.org/fulldisclosure/2020/Aug/9
- https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2020-051/

