Results 1 to 9 of 9

Thread: SugarCRM Unspecified SQL Injection Vulnerability

  1. #1
    kinshibuya's Avatar
    kinshibuya is offline A Sugar Hero
    Join Date
    Jul 2008
    Location
    brasil
    Posts
    521

    Default SugarCRM Unspecified SQL Injection Vulnerability

    Hi!
    I got this e-mail, warning about an SQL vulnerability in sugarcrm. is this true? Am i obrigated to update to 5.2h of is there a pacth to solve this?

    Do you have VARM strategy implemented?

    (Vulnerability Assessment Remediation Management)

    If not, then implement it through the most reliable vulnerability intelligence source on the market.

    Implement it through Secunia.

    For more information visit:
    http://secunia.com/advisories/business_solutions/

    Alternatively request a call from a Secunia representative today to discuss how we can help you with our capabilities contact us at:
    sales@secunia.com

    ----------------------------------------------------------------------

    TITLE:
    SugarCRM Unspecified SQL Injection Vulnerability

    SECUNIA ADVISORY ID:
    SA36423

    VERIFY ADVISORY:
    http://secunia.com/advisories/36423/

    DESCRIPTION:
    A vulnerability has been reported in SugarCRM, which can be exploited by malicious users to conduct SQL injection attacks.

    Certain unspecified input is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

    The vulnerability is reported in versions 5.2.0g and prior, 5.0.0k and prior, and 4.5.1o and prior.

    SOLUTION:
    Update to version 5.2.0h, 5.0.0l, or 4.5.1p.

    PROVIDED AND/OR DISCOVERED BY:
    Takeshi Terada of Mitsui Bussan Secure Directions, reported via JPCERT/CC

    ORIGINAL ADVISORY:
    JVN:
    http://jvn.jp/en/jp/JVN31035930/index.html
    http://jvndb.jvn.jp/en/contents/2009...09-000056.html

    SugarCRM:
    http://www.sugarcrm.com/forums/showthread.php?t=50907
    http://www.sugarcrm.com/forums/showthread.php?t=50953

    ----------------------------------------------------------------------

    About:
    This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities.

    Subscribe:
    http://secunia.com/advisories/secuni...ty_advisories/

    Definitions: (Criticality, Where etc.)
    http://secunia.com/advisories/about_secunia_advisories/


    Please Note:
    Secunia recommends that you verify all advisories you receive by clicking the link.
    Secunia NEVER sends attached files with advisories.
    Secunia does not advise people to install third party patches, only use those supplied by the vendor.
    Priscila Kin Yamamoto Joranhezon
    Phone: +55 61 32010000
    priscila.joranhezon@nct.com.br
    NCT Informática Ltda

  2. #2
    Angel's Avatar
    Angel is offline Sugar Community Member
    Join Date
    Jul 2005
    Location
    Los Angeles
    Posts
    4,813

    Default Re: SugarCRM Unspecified SQL Injection Vulnerability

    It is real. If you use e-mail in Sugar, you should definitely upgrade.
    Regards,

    Angel Magaña
    Co-Author: Implementing SugarCRM 5.x (Packt Publishing -- Sept. 2010)
    Blog: http://cheleguanaco.blogspot.com.
    Twitter: @cheleguanaco.

    ________
    | Projects: |_____________________________________
    |
    | CandyWrapper (.NET Wrapper for SugarCRM SOAP API). Source now available on GitHub!
    | GoldMine to SugarCRM Express Conversion. Latest: 1.0.1.7 (Nov. 3, 2009)
    | CRM SkyDialer (Skype Integration). Latest: 1.0.2 (Feb. 17, 2010)
    | Round Robin Leads Assignment
    | Phone Number Formatter
    | CaseTwit (Twitter Integration)
    ______________________________________________

  3. #3
    kinshibuya's Avatar
    kinshibuya is offline A Sugar Hero
    Join Date
    Jul 2008
    Location
    brasil
    Posts
    521

    Default Re: SugarCRM Unspecified SQL Injection Vulnerability

    Hi.
    Thanks for the reply, And version 5.2.i also has this vulnerability.
    And what kind of email? I use campaigns
    Could you give more details on how this vulnerability works?
    Priscila Kin Yamamoto Joranhezon
    Phone: +55 61 32010000
    priscila.joranhezon@nct.com.br
    NCT Informática Ltda

  4. #4
    roblaus's Avatar
    roblaus is offline Sugar Community Member
    Join Date
    Dec 2006
    Location
    Vienna / Austria
    Posts
    2,850

    Default Re: SugarCRM Unspecified SQL Injection Vulnerability

    As it was said in your quoted mail (and by Sugar itself albeit without any reasons given): An upgrade to patch h or i should fix this issue.

    In my opinion such a vulnerability can only be exploited in the moment an email is imported into Sugar because that's the only possibility how outside code (hidden in an html email) may come in contact with your database.

    Since campaigns do import emails (via the bounce settings) they may pose a threat.

    But specialists may explain this better and in more detail...
    __________________________
    Robert Laussegger
    http://www.iscongroup.net

    Bei Fragen: support@iscon.at
    Die deutschen Sprachdateien für SugarCRM und das deutsche Handbuch gibt es hier: http://goo.gl/kPsAz
    Ab sofort auch mit 6.4.2

  5. #5
    kinshibuya's Avatar
    kinshibuya is offline A Sugar Hero
    Join Date
    Jul 2008
    Location
    brasil
    Posts
    521

    Default Re: SugarCRM Unspecified SQL Injection Vulnerability

    Ok. thanks for the reply! my sugar is too customized, i will upgrade on the future release of 5.3. I dont work with incoming emails just with sending email throw campaigns and geting click thru link, All users are restricted to import anything. Thanks for the reply you all.
    Priscila Kin Yamamoto Joranhezon
    Phone: +55 61 32010000
    priscila.joranhezon@nct.com.br
    NCT Informática Ltda

  6. #6
    nutri is offline Member
    Join Date
    Aug 2009
    Posts
    13

    Default Re: SugarCRM Unspecified SQL Injection Vulnerability

    I'm sure about the vulnerability and I do not use e-mail capabilities in Sugar but, probably used as mail client, receiving and viewing an email could be exploitable, not only importing mails. In the advisory there's no details about exploitation and I think, although some places said remote+no authentication, that's not correct.
    Anyway, if SQL Injection exists, as it is, update.

  7. #7
    judgej is offline Sugar Community Member
    Join Date
    Feb 2007
    Posts
    58

    Default Re: SugarCRM Unspecified SQL Injection Vulnerability

    I know this is an ancient thread, but I'm on 6.2.0 and I have noticed the SOAP API has an SQL injection vulnerability (I noticed because an Outlook plugin was sending emails with quotes in, and resulting in database errors).

    So - did this never get fixed? Is it perhaps a different vulnerability? Why on earth is there ANY code in Sugar that allows this to happen? Does Sugar not used a database layer to handle all escaping and inserting of parameters into SQL? It just seems like one of those golden rules that we web developers had learnt a decade ago - it is unbelievable that SQL injection gets to see the light of day still.

    -- Jason

  8. #8
    Angel's Avatar
    Angel is offline Sugar Community Member
    Join Date
    Jul 2005
    Location
    Los Angeles
    Posts
    4,813

    Default Re: SugarCRM Unspecified SQL Injection Vulnerability

    Well, in the end, things are still coded by humans and *all* humans make mistakes.

    That being said, it sounds like a different vulnerability, assuming it is confirmed as such.
    Regards,

    Angel Magaña
    Co-Author: Implementing SugarCRM 5.x (Packt Publishing -- Sept. 2010)
    Blog: http://cheleguanaco.blogspot.com.
    Twitter: @cheleguanaco.

    ________
    | Projects: |_____________________________________
    |
    | CandyWrapper (.NET Wrapper for SugarCRM SOAP API). Source now available on GitHub!
    | GoldMine to SugarCRM Express Conversion. Latest: 1.0.1.7 (Nov. 3, 2009)
    | CRM SkyDialer (Skype Integration). Latest: 1.0.2 (Feb. 17, 2010)
    | Round Robin Leads Assignment
    | Phone Number Formatter
    | CaseTwit (Twitter Integration)
    ______________________________________________

  9. #9
    jmertic is offline Sugar Community Manager
    Join Date
    Dec 2007
    Posts
    2,224

    Default Re: SugarCRM Unspecified SQL Injection Vulnerability

    Can you confirm that this is part of the latest 6.2.3 release? We've had several security vulnerabilities fixed since then.

    If not, then send an email to secure@sugarcrm.com with the issue.
    John Mertic
    Sugar Community Manager

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Vulnerability testing of SugarCRM
    By pkruithofjr in forum Help
    Replies: 11
    Last Post: 2009-07-09, 10:56 PM
  2. Sugar Login Susceptible to SQL Injection Attack
    By Kalendrinn in forum Developer Help
    Replies: 2
    Last Post: 2008-01-10, 02:39 AM
  3. Replies: 0
    Last Post: 2007-11-04, 05:28 PM
  4. SQL Injection/Overwrite
    By sunside in forum General Discussion
    Replies: 4
    Last Post: 2007-04-18, 11:17 PM
  5. SugarCRM email XSS vulnerability and how to protect yourself
    By ayavilevich in forum General Discussion
    Replies: 12
    Last Post: 2006-10-14, 05:39 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •