High severity8.8NVD Advisory· Published Dec 19, 2021· Updated Jun 17, 2026
CVE-2021-45041
CVE-2021-45041
Description
SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*range: <7.12.2
- cpe:2.3:a:salesagility:suitecrm:8.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:salesagility:suitecrm:8.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:salesagility:suitecrm:8.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:salesagility:suitecrm:8.0:beta:*:*:*:*:*:*
- cpe:2.3:a:salesagility:suitecrm:8.0:rc:*:*:*:*:*:*
- SuiteCRM/SuiteCRMdescription
Patches
Vulnerability mechanics
References
2- docs.suitecrm.com/8.x/admin/releases/8.0/nvdPatchRelease NotesVendor Advisory
- docs.suitecrm.com/admin/releases/7.12.x/nvdPatchRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.