CVE-2011-0745

medium
Published 2011-03-16 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.0

Description

SugarCRM before 6.1.3 does not properly handle reloads and direct requests for a warning page produced by a certain duplicate check, which allows remote authenticated users to discover (1) the names of customers via a ShowDuplicates action to the Accounts module, reachable through index.php; or (2) the names of contact persons via a ShowDuplicates action to the Contacts module, reachable through index.php.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-35467 webapps php verified
RedTeam Pentesting GmbH ยท 2011-03-15

SugarCRM 6.1.1 - Information Disclosure

Source code queued for fetch โ€” refresh in a moment.

Application impact

VendorProductVersionsFixed
sugarcrmsugarcrm{"endIncluding":"6.1.2"}
sugarcrmsugarcrm1.0
sugarcrmsugarcrm1.0f
sugarcrmsugarcrm1.0g
sugarcrmsugarcrm1.1
sugarcrmsugarcrm1.1a
sugarcrmsugarcrm1.1b
sugarcrmsugarcrm1.1c
sugarcrmsugarcrm1.1d
sugarcrmsugarcrm1.1e
sugarcrmsugarcrm1.1f
sugarcrmsugarcrm1.5d
sugarcrmsugarcrm2.0.1
sugarcrmsugarcrm2.0.1a
sugarcrmsugarcrm2.0.1c
sugarcrmsugarcrm3.0.1
sugarcrmsugarcrm3.5
sugarcrmsugarcrm3.5.1
sugarcrmsugarcrm4.0
sugarcrmsugarcrm4.0.1
sugarcrmsugarcrm4.1
sugarcrmsugarcrm4.2
sugarcrmsugarcrm4.2.1
sugarcrmsugarcrm4.5.0
sugarcrmsugarcrm4.5.0f
sugarcrmsugarcrm4.5.1
sugarcrmsugarcrm4.5.1i
sugarcrmsugarcrm4.5.1o
sugarcrmsugarcrm5.0.0
sugarcrmsugarcrm5.0.0h
sugarcrmsugarcrm5.0.0k
sugarcrmsugarcrm5.1.0
sugarcrmsugarcrm5.1.0-beta
sugarcrmsugarcrm5.1c
sugarcrmsugarcrm5.1l
sugarcrmsugarcrm5.2.0g
sugarcrmsugarcrm5.2a
sugarcrmsugarcrm5.2c
sugarcrmsugarcrm5.2d
sugarcrmsugarcrm5.2e
sugarcrmsugarcrm5.2f
sugarcrmsugarcrm5.2g
sugarcrmsugarcrm5.2h
sugarcrmsugarcrm5.5
sugarcrmsugarcrm5.5.0
sugarcrmsugarcrm5.5.1
sugarcrmsugarcrm5.5.2
sugarcrmsugarcrm5.5.3
sugarcrmsugarcrm5.5.4
sugarcrmsugarcrm5.5a
sugarcrmsugarcrm6.0
sugarcrmsugarcrm6.0.1
sugarcrmsugarcrm6.0.2
sugarcrmsugarcrm6.0.3
sugarcrmsugarcrm6.1.0
sugarcrmsugarcrm6.1.1

References

CWEs

CWE-20

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.