Loading
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.
Use CWE-20, Sugarcrm vendor hub and Sugarcrm product page to widen CVE-2012-0694 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-22952, CVE-2020-7472 and CVE-2023-46816 for nearby disclosures in the same product family.