High severity7.2NVD Advisory· Published Apr 15, 2022· Updated Jun 17, 2026
CVE-2022-27474
CVE-2022-27474
Description
SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field.
Affected products
3- cpe:2.3:a:salesagility:suitecrm:7.11.23:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- github.com/Mount4in/Mount4in.github.io/blob/master/poc.pynvdExploitThird Party Advisory
- github.com/Mount4in/Mount4in.github.io/blob/master/suitecrm.docxnvdThird Party Advisory
News mentions
0No linked articles in our index yet.