Suitecrm
by Salesagility
Source repositories
CVEs (106)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-0756 | Med | 0.00 | 6.5 | 0.01 | Mar 7, 2022 | Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5. | ||
| CVE-2022-0755 | Med | 0.00 | 4.3 | 0.01 | Mar 7, 2022 | Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5. | ||
| CVE-2022-0754 | Med | 0.00 | 6.5 | 0.01 | Mar 7, 2022 | SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5. | ||
| CVE-2021-25961 | Hig | 0.00 | 8.0 | 0.01 | Sep 29, 2021 | In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id. | ||
| CVE-2021-25960 | Hig | 0.00 | 8.0 | 0.01 | Sep 29, 2021 | In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). A low privileged attacker can use accounts module to inject payloads in the input fields. When an administrator access… | ||
| CVE-2018-20816 | Med | 0.00 | 6.1 | 0.01 | Apr 5, 2019 | An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a… |
- risk 0.00cvss 6.5epss 0.01
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
- risk 0.00cvss 4.3epss 0.01
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
- risk 0.00cvss 6.5epss 0.01
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5.
- risk 0.00cvss 8.0epss 0.01
In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id.
- risk 0.00cvss 8.0epss 0.01
In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). A low privileged attacker can use accounts module to inject payloads in the input fields. When an administrator access…
- risk 0.00cvss 6.1epss 0.01
An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a…
Page 6 of 6