Suitecrm

Suite CRM

34 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 05.04.2026 20:45:18
  • Zuletzt bearbeitet 07.04.2026 13:20:35

SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView action that allows authenticated attackers to manipulate database queries. Attackers can append SQL code to the record parameter ...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 05.04.2026 20:45:17
  • Zuletzt bearbeitet 07.04.2026 13:20:35

SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the parentTab parameter. Attackers can send GET requests to the email module with malicious parent...

  • EPSS 0.03%
  • Veröffentlicht 19.03.2026 23:13:08
  • Zuletzt bearbeitet 23.03.2026 16:42:53

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3, the `RecordHandler::getRecord()` method retrieves any record by module and ID without checking the current user's ACL v...

  • EPSS 0.07%
  • Veröffentlicht 19.03.2026 23:12:11
  • Zuletzt bearbeitet 23.03.2026 16:48:58

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions up to and including 8.9.2 contain an unsafe deserialization vulnerability in the SavedSearch filter processing component that allows an...

  • EPSS 0.04%
  • Veröffentlicht 19.03.2026 23:10:59
  • Zuletzt bearbeitet 23.03.2026 16:49:25

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3, an authenticated API endpoint allows any user to retrieve detailed information about any other user, including their pa...

  • EPSS 0.17%
  • Veröffentlicht 19.03.2026 23:09:07
  • Zuletzt bearbeitet 23.03.2026 16:57:46

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an LDAP Injection vulnerability exists in the SuiteCRM authentication flow. The application fails to properl...

  • EPSS 0.05%
  • Veröffentlicht 19.03.2026 23:08:11
  • Zuletzt bearbeitet 23.03.2026 16:56:51

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a SQL Injection vulnerability exists in the SuiteCRM authentication mechanisms when directory support is ena...

  • EPSS 0.03%
  • Veröffentlicht 19.03.2026 23:05:16
  • Zuletzt bearbeitet 23.03.2026 16:46:51

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the SuiteCRM REST API V8 has missing ACL (Access Control List) checks on several endpoints, allowing authent...

  • EPSS 0.03%
  • Veröffentlicht 19.03.2026 23:04:12
  • Zuletzt bearbeitet 24.03.2026 13:46:52

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, it is possible to create PDF templates with `<img>` tags. When a PDF is exported using this template, the co...

  • EPSS 0.04%
  • Veröffentlicht 19.03.2026 23:02:19
  • Zuletzt bearbeitet 24.03.2026 13:58:40

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the value of the return_id request parameter is copied into the value of an HTML tag attribute which is an e...