Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54779 | SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur. |
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 14 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Sun, 13 Jul 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Sun, 13 Jul 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-03T19:34:25.863Z
Reserved: 2025-07-13T00:00:00.000Z
Link: CVE-2024-58258
Updated: 2025-11-03T19:34:25.863Z
Status : Deferred
Published: 2025-07-13T22:15:23.090
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-58258
No data.
OpenCVE Enrichment
Updated: 2025-07-14T22:45:33Z
EUVD