CVE-2008-2045

SugarCRM 4.5.1 and 5.0.0 - Path Traversal via URL Parameter in Feed.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-2045. PoCs published by Roberto Suggi Liverani.

AI-analyzed exploit summary This is a detailed writeup describing a local file disclosure vulnerability in SugarCRM Community Edition versions 4.5.1 and 5.0.0. The flaw allows an attacker to read arbitrary local files by exploiting improper input validation in the RSS module, which creates a cached file with the contents of the specified local file.

Description

Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to read arbitrary files via a full path in the URL parameter to modules/Feeds/Feed.php, which places the contents into a related cache file in the .cache/feeds directory.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Roberto Suggi Liverani · textwebappsphp
https://www.exploit-db.com/exploits/5521

This is a detailed writeup describing a local file disclosure vulnerability in SugarCRM Community Edition versions 4.5.1 and 5.0.0. The flaw allows an attacker to read arbitrary local files by exploiting improper input validation in the RSS module, which creates a cached file with the contents of the specified local file.

Classification
Writeup 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: SugarCRM Community Edition 4.5.1 and 5.0.0
No auth needed
Prerequisites: Access to the SugarCRM application · Ability to submit a crafted RSS feed URL
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/491417/100/0/threaded
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28981
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1388/references
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3844
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30002
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/42087
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5521

Scores

EPSS 0.0520
EPSS Percentile 91.4%

Details

CWE
CWE-22
Status published
Products (2)
sugarcrm/sugarcrm 4.5.1
sugarcrm/sugarcrm 5.0.0
Published May 01, 2008
Tracked Since Feb 18, 2026