3.7
CVE-2025-54787
- EPSS 0.22%
- Veröffentlicht 07.08.2025 21:15:39
- Zuletzt bearbeitet 12.08.2025 20:54:29
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
SuiteCRM: Improper Authorization for attachment downloads
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vulnerability in SuiteCRM version 7.14.6 which allows unauthenticated downloads of any file from the upload-directory, as long as it is named by an ID (e.g. attachments). An unauthenticated attacker could download internal files when he discovers a valid file-ID. Valid IDs could be brute-forced, but this is quite time-consuming as the file-IDs are usually UUIDs. This issue is fixed in version 7.14.7.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Salesagility ≫ Suite CRM Version >= 8.6.0 < 8.8.1
Salesagility ≫ Suite CRM Version7.14.6
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.12 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 3.7 | 2.2 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-285 Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
https://docs.suitecrm.com/admin/releases/7.14.x/#_7_14_7
https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-8r72-224q-g9fv