Notified: July 15, 2009 Updated: January 11, 2013
Statement Date: April 30, 2010
Affected
You can download any of the 2.8 version and then do a code update from the GUI. This will get you the latest code. The insecure RSS code was removed in the newer version.
We are not aware of further vendor information regarding this vulnerability.
Updated: January 11, 2013
Affected
No statement is currently available from the vendor regarding this vulnerability.
We are not aware of further vendor information regarding this vulnerability.
http://www.security-assessment.com/files/advisories/2008-04-29_SugarCRM_local_file_disclosure.pdf
Notified: July 15, 2009 Updated: January 11, 2013
Statement Date: April 30, 2010
Affected
You can download any of the 2.8 version and then do a code update from the GUI. This will get you the latest code. The insecure RSS code was removed in the newer version.
We are not aware of further vendor information regarding this vulnerability.