A vulnerability in the Document module allows a malicious authenticated user to upload files with arbitrary names. These files, depending on the server’s configuration, may then be callable remotely.
Copyright 2004-2008 SugarCRM Inc.
Product License