<?xml-stylesheet type="text/xsl" href="https://sugarclub.sugarai.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Action needed - January 4, 2023: SugarCRM Hotfix for critical security vulnerability</title><link>/explore/product-updates/b/sugar-serve-updates/posts/january-4-2023-critical-security-hotfix</link><description>At SugarCRM, we take seriously the security and the protection of your systems and data.
Today (January 4, 2023), we are publicly announcing the availability of v1.1 of &amp;quot;hotfix 91155 XXXX&amp;quot; for all Sugar Sell, Serve, Enterprise, Professional, and Ulti</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Action needed - January 4, 2023: SugarCRM Hotfix for critical security vulnerability</title><link>https://sugarclub.sugarai.com/explore/product-updates/b/sugar-serve-updates/posts/january-4-2023-critical-security-hotfix</link><pubDate>Thu, 05 Jan 2023 23:40:19 GMT</pubDate><guid isPermaLink="false">5c521d64-519d-47a6-9065-134618b211bf:c92fa2db-b693-41a5-b15e-d8cf96caaad9</guid><dc:creator>Alex Nassi</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;span&gt;Please review the most recent information and updates&amp;nbsp;&lt;/span&gt;&lt;a href="/engage/b/sugar-news/posts/jan-5-2023-security-vulnerability-update"&gt;here&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;&lt;img src="https://sugarclub.sugarai.com/aggbug?PostID=3105&amp;AppID=43&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: Action needed - January 4, 2023: SugarCRM Hotfix for critical security vulnerability</title><link>https://sugarclub.sugarai.com/explore/product-updates/b/sugar-serve-updates/posts/january-4-2023-critical-security-hotfix</link><pubDate>Thu, 05 Jan 2023 18:36:39 GMT</pubDate><guid isPermaLink="false">5c521d64-519d-47a6-9065-134618b211bf:c92fa2db-b693-41a5-b15e-d8cf96caaad9</guid><dc:creator>Murray Crane</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;Turns out&amp;nbsp;our on-site was&amp;nbsp;&amp;quot;exploited&amp;quot; (which I discovered while applying the hot fix). Not a problem, killed everything that was running and (after taking copies of the payload) deleted it all. Would like to thank Wilfred for posting that link, otherwise I&amp;#39;d have had no real information about this. Only other complaint I&amp;#39;d make is that the installation instructions were woefully lacking - assumed the hot fix applied via the &amp;quot;Upgrade Wizard&amp;quot;, but that threw an error that led me down a rabbit hole that ended with me &amp;quot;discovering&amp;quot; the Module Loader. A one-line &amp;quot;Apply the hot fix with the Module Loader.&amp;quot; would have fixed that so quickly and easily...&lt;/p&gt;&lt;img src="https://sugarclub.sugarai.com/aggbug?PostID=3105&amp;AppID=43&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: Action needed - January 4, 2023: SugarCRM Hotfix for critical security vulnerability</title><link>https://sugarclub.sugarai.com/explore/product-updates/b/sugar-serve-updates/posts/january-4-2023-critical-security-hotfix</link><pubDate>Thu, 05 Jan 2023 16:37:49 GMT</pubDate><guid isPermaLink="false">5c521d64-519d-47a6-9065-134618b211bf:c92fa2db-b693-41a5-b15e-d8cf96caaad9</guid><dc:creator>Wilfried Pascault</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;Is there a link between this fix and the 0day file upload vulnerability published on Full Disclosure security list ?&amp;nbsp;&lt;br /&gt;&lt;a rel="nofollow" target="_blank" href="https://seclists.org/fulldisclosure/2022/Dec/31"&gt;seclists.org/.../31&lt;/a&gt;&lt;/p&gt;&lt;img src="https://sugarclub.sugarai.com/aggbug?PostID=3105&amp;AppID=43&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: Action needed - January 4, 2023: SugarCRM Hotfix for critical security vulnerability</title><link>https://sugarclub.sugarai.com/explore/product-updates/b/sugar-serve-updates/posts/january-4-2023-critical-security-hotfix</link><pubDate>Thu, 05 Jan 2023 14:13:05 GMT</pubDate><guid isPermaLink="false">5c521d64-519d-47a6-9065-134618b211bf:c92fa2db-b693-41a5-b15e-d8cf96caaad9</guid><dc:creator>Olaf Doernenburg</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;Hi,&amp;nbsp;&lt;/p&gt;
&lt;p&gt;since we got only this message, we are not sure what is meant by&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&amp;quot;If you have not yet applied the hotfix released earlier today, you need only download and apply v1.1 Hotfix 91155 XXXX&lt;/span&gt;&amp;quot;&lt;/p&gt;
&lt;p&gt;Had there been a release which was not announced?&amp;nbsp;&lt;/p&gt;
&lt;p&gt;And which security issues are fixed, usually we get a list of the impacts.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks and best regards&lt;/p&gt;
&lt;p&gt;Olaf&amp;nbsp;&lt;/p&gt;&lt;img src="https://sugarclub.sugarai.com/aggbug?PostID=3105&amp;AppID=43&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item></channel></rss>