Back to Database
Status published
High
CVE-2024-58258
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in...
Vulnerability Description
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-58258
Credits & Attribution
No credits recorded in the NVD database.
More from SugarCRM
View All →Affected Vendor
SugarCRM
View all reports →Affected Software
SugarCRM
Vulnerable Versions:
0, 14
Timeline
Official Publish:
July 13th, 2025
Last Modified:
November 3rd, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N