Vendor CVEs
Salesagility
All CVEs
106 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-42840 | Hig | 0.65 | 8.8 | 0.59 | Oct 22, 2021 | SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP… | ||
| CVE-2020-28328 | Hig | 0.65 | 8.8 | 0.63 | Nov 6, 2020 | SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root. | ||
| CVE-2022-50589 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2025 | SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code. | ||
| CVE-2024-1644 | Cri | 0.64 | 9.9 | 0.01 | Feb 20, 2024 | Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI. | ||
| CVE-2021-45899 | Cri | 0.64 | 9.8 | 0.02 | Jan 28, 2022 | SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution. | ||
| CVE-2021-45898 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2022 | SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion. | ||
| CVE-2020-8786 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4). | ||
| CVE-2020-8785 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4). | ||
| CVE-2020-8784 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4). | ||
| CVE-2020-8783 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4). | ||
| CVE-2020-8803 | Cri | 0.64 | 9.8 | 0.03 | Feb 13, 2020 | SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list. | ||
| CVE-2020-8802 | Cri | 0.64 | 9.8 | 0.03 | Feb 13, 2020 | SuiteCRM through 7.11.11 has Incorrect Access Control via action_saveHTMLField Bean Manipulation. | ||
| CVE-2019-14454 | Cri | 0.64 | 9.8 | 0.02 | Oct 2, 2019 | SuiteCRM 7.11.x and 7.10.x before 7.11.8 and 7.10.20 is vulnerable to vertical privilege escalation. | ||
| CVE-2019-13335 | Cri | 0.64 | 9.8 | 0.01 | Oct 2, 2019 | SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF. | ||
| CVE-2019-12601 | Cri | 0.64 | 9.8 | 0.01 | Jun 7, 2019 | SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 3 of 3). | ||
| CVE-2019-12600 | Cri | 0.64 | 9.8 | 0.01 | Jun 7, 2019 | SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3). | ||
| CVE-2019-12599 | Cri | 0.64 | 9.8 | 0.01 | Jun 7, 2019 | SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection. | ||
| CVE-2019-12598 | Cri | 0.64 | 9.8 | 0.01 | Jun 7, 2019 | SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3). | ||
| CVE-2019-6506 | Cri | 0.64 | 9.8 | 0.02 | Apr 2, 2019 | SuiteCRM before 7.8.28, 7.9.x and 7.10.x before 7.10.15, and 7.11.x before 7.11.3 allows SQL Injection. | ||
| CVE-2022-23940 | Hig | 0.62 | 8.8 | 0.53 | Mar 10, 2022 | SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a… | ||
| CVE-2024-36412 | Cri | 0.58 | 10.0 | 0.06 | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for a SQL injection attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue. | ||
| CVE-2021-45897 | Hig | 0.58 | 8.8 | 0.05 | Jan 28, 2022 | SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution. | ||
| CVE-2025-64492 | Hig | 0.57 | 8.8 | 0.00 | Nov 8, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0 and below contain a time-based blind SQL Injection vulnerability. This vulnerability allows an authenticated attacker to infer data from the database by… | ||
| CVE-2025-54788 | Hig | 0.57 | 8.8 | 0.00 | Aug 7, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, the InboundEmail module allows the arbitrary execution of queries in the backend database, leading to SQL injection. This can have wide-reaching… | ||
| CVE-2025-54785 | Hig | 0.57 | 8.8 | 0.00 | Aug 7, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanitized before it is passed to the unserialize function, which could lead to penetration, privilege… | ||
| CVE-2022-45185 | Hig | 0.57 | 8.8 | 0.01 | Jan 7, 2025 | An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution. | ||
| CVE-2024-50332 | Hig | 0.57 | 8.8 | 0.00 | Nov 5, 2024 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Insufficient input value validation causes Blind SQL injection in DeleteRelationShip. This issue has been addressed in versions 7.14.6 and 8.7.1. Users are advised to… | ||
| CVE-2024-49772 | Hig | 0.57 | 8.8 | 0.00 | Nov 5, 2024 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In SuiteCRM versions 7.14.4, poor input validation allows authenticated user do a SQL injection attack. Authenticated user with low pivilege can leak all data in database.… | ||
| CVE-2021-41597 | Hig | 0.57 | 8.8 | 0.01 | Jan 12, 2022 | SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive. | ||
| CVE-2021-45041 | Hig | 0.57 | 8.8 | 0.02 | Dec 19, 2021 | SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date. | ||
| CVE-2021-41869 | Hig | 0.57 | 8.8 | 0.02 | Oct 4, 2021 | SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation. | ||
| CVE-2020-8800 | Hig | 0.57 | 8.8 | 0.03 | Feb 13, 2020 | SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection. | ||
| CVE-2019-18784 | Cri | 0.57 | 9.8 | 0.01 | Nov 6, 2019 | SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection. | ||
| CVE-2024-36416 | Hig | 0.56 | 8.6 | 0.02 | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a deprecated v4 API example with no log rotation allows denial of service by logging excessive data. Versions 7.14.4 and 8.6.1 contain a fix for this issue. | ||
| CVE-2024-36411 | Cri | 0.55 | 9.6 | 0.00 | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in EmailUIAjax displayView controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue. | ||
| CVE-2024-36410 | Cri | 0.55 | 9.6 | 0.00 | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in EmailUIAjax messages count controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue. | ||
| CVE-2024-36409 | Cri | 0.55 | 9.6 | 0.00 | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in Tree data entry point. Versions 7.14.4 and 8.6.1 contain a fix for this issue. | ||
| CVE-2024-36408 | Cri | 0.55 | 9.6 | 0.00 | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in the `Alerts` controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue. | ||
| CVE-2025-64490 | Hig | 0.54 | 8.3 | 0.00 | Nov 8, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0 allow a low-privileged user with a restrictive role to view and create work items through the Resource Calendar and… | ||
| CVE-2022-45186 | Hig | 0.53 | 8.1 | 0.01 | Jan 7, 2025 | An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database. | ||
| CVE-2024-36415 | Cri | 0.52 | 9.1 | 0.01 | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in uploaded file verification in products allows for remote code execution. Versions 7.14.4 and 8.6.1 contain a fix for this issue. | ||
| CVE-2024-36413 | Hig | 0.51 | 8.9 | 0.00 | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in the import module error view allows for a cross-site scripting attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue. | ||
| CVE-2020-15301 | Hig | 0.51 | 7.8 | 0.01 | Nov 18, 2020 | SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation. | ||
| CVE-2015-5946 | Hig | 0.51 | 7.8 | 0.02 | Aug 7, 2017 | Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension. | ||
| CVE-2024-45392 | Hig | 0.50 | 7.7 | 0.00 | Sep 5, 2024 | SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Versions 7.14.5 and 8.6.2 contain a patch for the issue. | ||
| CVE-2022-27474 | Hig | 0.49 | 7.2 | 0.23 | Apr 15, 2022 | SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field. | ||
| CVE-2020-8787 | Hig | 0.49 | 7.5 | 0.01 | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted. | ||
| CVE-2024-36418 | Hig | 0.48 | 8.5 | 0.01 | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in connectors allows an authenticated user to perform a remote code execution attack. Versions 7.14.4 and 8.6.1 contain a fix for this… | ||
| CVE-2024-49774 | Hig | 0.47 | 7.2 | 0.01 | Nov 5, 2024 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM relies on the blacklist of functions/methods to prevent installation of malicious MLPs. But this checks can be bypassed with some syntax constructions. SuiteCRM… | ||
| CVE-2020-8801 | Hig | 0.47 | 7.2 | 0.03 | Feb 13, 2020 | SuiteCRM through 7.11.11 allows PHAR Deserialization. |
- risk 0.65cvss 8.8epss 0.59
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP…
- risk 0.65cvss 8.8epss 0.63
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.
- risk 0.64cvss 9.8epss 0.01
SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code.
- risk 0.64cvss 9.9epss 0.01
Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI.
- risk 0.64cvss 9.8epss 0.02
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
- risk 0.64cvss 9.8epss 0.01
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.
- risk 0.64cvss 9.8epss 0.01
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4).
- risk 0.64cvss 9.8epss 0.01
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4).
- risk 0.64cvss 9.8epss 0.01
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4).
- risk 0.64cvss 9.8epss 0.01
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4).
- risk 0.64cvss 9.8epss 0.03
SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.
- risk 0.64cvss 9.8epss 0.03
SuiteCRM through 7.11.11 has Incorrect Access Control via action_saveHTMLField Bean Manipulation.
- risk 0.64cvss 9.8epss 0.02
SuiteCRM 7.11.x and 7.10.x before 7.11.8 and 7.10.20 is vulnerable to vertical privilege escalation.
- risk 0.64cvss 9.8epss 0.01
SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.
- risk 0.64cvss 9.8epss 0.01
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 3 of 3).
- risk 0.64cvss 9.8epss 0.01
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3).
- risk 0.64cvss 9.8epss 0.01
SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection.
- risk 0.64cvss 9.8epss 0.01
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3).
- risk 0.64cvss 9.8epss 0.02
SuiteCRM before 7.8.28, 7.9.x and 7.10.x before 7.10.15, and 7.11.x before 7.11.3 allows SQL Injection.
- risk 0.62cvss 8.8epss 0.53
SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a…
- risk 0.58cvss 10.0epss 0.06
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for a SQL injection attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
- risk 0.58cvss 8.8epss 0.05
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.
- risk 0.57cvss 8.8epss 0.00
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0 and below contain a time-based blind SQL Injection vulnerability. This vulnerability allows an authenticated attacker to infer data from the database by…
- risk 0.57cvss 8.8epss 0.00
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, the InboundEmail module allows the arbitrary execution of queries in the backend database, leading to SQL injection. This can have wide-reaching…
- risk 0.57cvss 8.8epss 0.00
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanitized before it is passed to the unserialize function, which could lead to penetration, privilege…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.
- risk 0.57cvss 8.8epss 0.00
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Insufficient input value validation causes Blind SQL injection in DeleteRelationShip. This issue has been addressed in versions 7.14.6 and 8.7.1. Users are advised to…
- risk 0.57cvss 8.8epss 0.00
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In SuiteCRM versions 7.14.4, poor input validation allows authenticated user do a SQL injection attack. Authenticated user with low pivilege can leak all data in database.…
- risk 0.57cvss 8.8epss 0.01
SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.
- risk 0.57cvss 8.8epss 0.02
SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.
- risk 0.57cvss 8.8epss 0.02
SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation.
- risk 0.57cvss 8.8epss 0.03
SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.
- risk 0.57cvss 9.8epss 0.01
SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection.
- risk 0.56cvss 8.6epss 0.02
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a deprecated v4 API example with no log rotation allows denial of service by logging excessive data. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
- risk 0.55cvss 9.6epss 0.00
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in EmailUIAjax displayView controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
- risk 0.55cvss 9.6epss 0.00
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in EmailUIAjax messages count controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
- risk 0.55cvss 9.6epss 0.00
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in Tree data entry point. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
- risk 0.55cvss 9.6epss 0.00
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in the `Alerts` controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
- risk 0.54cvss 8.3epss 0.00
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0 allow a low-privileged user with a restrictive role to view and create work items through the Resource Calendar and…
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.
- risk 0.52cvss 9.1epss 0.01
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in uploaded file verification in products allows for remote code execution. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
- risk 0.51cvss 8.9epss 0.00
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in the import module error view allows for a cross-site scripting attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
- risk 0.51cvss 7.8epss 0.01
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.
- risk 0.51cvss 7.8epss 0.02
Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.
- risk 0.50cvss 7.7epss 0.00
SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Versions 7.14.5 and 8.6.2 contain a patch for the issue.
- risk 0.49cvss 7.2epss 0.23
SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field.
- risk 0.49cvss 7.5epss 0.01
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted.
- risk 0.48cvss 8.5epss 0.01
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in connectors allows an authenticated user to perform a remote code execution attack. Versions 7.14.4 and 8.6.1 contain a fix for this…
- risk 0.47cvss 7.2epss 0.01
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM relies on the blacklist of functions/methods to prevent installation of malicious MLPs. But this checks can be bypassed with some syntax constructions. SuiteCRM…
- risk 0.47cvss 7.2epss 0.03
SuiteCRM through 7.11.11 allows PHAR Deserialization.
Page 1 of 3