Unrated severityNVD Advisory· Published Sep 5, 2024· Updated Sep 5, 2024
SuiteCRM has wrong deletion permission checks on API delete call
CVE-2024-45392
Description
SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Versions 7.14.5 and 8.6.2 contain a patch for the issue.
Affected products
1- Range: < 7.14.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- docs.suitecrm.com/admin/releases/7.14.x/mitrex_refsource_MISC
- github.com/salesagility/SuiteCRM/security/advisories/GHSA-8qfx-h7pm-2587mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.