Medium severity4.3NVD Advisory· Published Jun 10, 2024· Updated Jun 17, 2026
CVE-2024-36419
CVE-2024-36419
Description
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prior to 8.6.1 allows for Host Header Injection when directly accessing the /legacy route. Version 8.6.1 contains a patch for the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*range: <8.6.1
- (no CPE)range: < 8.6.1
Patches
Vulnerability mechanics
References
1- github.com/salesagility/SuiteCRM-Core/security/advisories/GHSA-3323-hjq3-c6vcnvdThird Party Advisory
News mentions
0No linked articles in our index yet.