CVE-2012-0694 is a critical vulnerability affecting SugarCRM Community Edition versions up to 6.3.1, stemming from the unsafe use of "unserialize()" with user-controlled input. This allows unauthenticated remote attackers to execute arbitrary PHP code on the server, leading to complete system compromise. With a CVSS score of 9.8, the attack requires no user interaction and has high confidentiality, integrity, and availability impacts. Exploit code is publicly available, including a Metasploit module, and the vulnerability has received significant community discussion and media coverage, indicating its widespread awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.3.1CPE matchmatch criteria | cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.