7.5

CVE-2020-8787

SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SalesagilitySuite CRM Version >= 7.10.0 < 7.10.23
SalesagilitySuite CRM Version >= 7.11.0 < 7.11.11
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.88% 0.543
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://docs.suitecrm.com/admin/releases/7.10.x/#_7_10_23
Vendor Advisory
Release Notes
https://docs.suitecrm.com/admin/releases/7.11.x/#_7_11_11
Vendor Advisory
Release Notes