CVE-2024-58258 - CERT CVE
ID CVE-2024-58258
Sažetak SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.
Reference
CVSS
Base: 7.2
Impact: 2.7
Exploitability:3.9
Pristup
VektorSloženostAutentikacija
NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
LOW LOW NONE
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Zadnje važnije ažuriranje 13-07-2025 - 22:15
Objavljeno 13-07-2025 - 22:15