CVE-2024-50332
- EPSS 0.12%
- Veröffentlicht 05.11.2024 19:15:06
- Zuletzt bearbeitet 13.11.2024 18:59:49
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Insufficient input value validation causes Blind SQL injection in DeleteRelationShip. This issue has been addressed in versions 7.14.6 and 8.7.1...
CVE-2024-50333
- EPSS 0.08%
- Veröffentlicht 05.11.2024 19:15:06
- Zuletzt bearbeitet 13.11.2024 20:10:45
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. User input is not validated and is written to the filesystem. The ParserLabel::addLabels() function can be used to write attacker-controlled dat...
CVE-2024-49772
- EPSS 0.12%
- Veröffentlicht 05.11.2024 19:15:05
- Zuletzt bearbeitet 13.11.2024 20:19:54
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In SuiteCRM versions 7.14.4, poor input validation allows authenticated user do a SQL injection attack. Authenticated user with low pivilege can...
CVE-2024-45392
- EPSS 0.09%
- Veröffentlicht 05.09.2024 17:15:12
- Zuletzt bearbeitet 06.09.2024 13:24:34
SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Versions 7.14.5 and 8.6.2 contain a patch for the issu...
CVE-2024-36419
- EPSS 0.27%
- Veröffentlicht 10.06.2024 22:15:11
- Zuletzt bearbeitet 21.11.2024 09:22:08
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prior to 8.6.1 allows for Host Header Injection when directly accessing the `/legacy` route. Version 8.6.1 contains a patch for the is...
CVE-2024-36418
- EPSS 6.21%
- Veröffentlicht 10.06.2024 21:15:52
- Zuletzt bearbeitet 21.11.2024 09:22:08
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in connectors allows an authenticated user to perform a remote code execution attack. Versions 7.14.4 and 8.6....
CVE-2024-36413
- EPSS 0.46%
- Veröffentlicht 10.06.2024 20:15:14
- Zuletzt bearbeitet 21.11.2024 09:22:07
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in the import module error view allows for a cross-site scripting attack. Versions 7.14.4 and 8.6.1 contain a ...
CVE-2024-36414
- EPSS 0.26%
- Veröffentlicht 10.06.2024 20:15:14
- Zuletzt bearbeitet 21.11.2024 09:22:07
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in the connectors file verification allows for a server-side request forgery attack. Versions 7.14.4 and 8.6.1...
CVE-2024-36415
- EPSS 5.84%
- Veröffentlicht 10.06.2024 20:15:14
- Zuletzt bearbeitet 21.11.2024 09:22:07
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in uploaded file verification in products allows for remote code execution. Versions 7.14.4 and 8.6.1 contain ...
CVE-2024-36416
- EPSS 44.7%
- Veröffentlicht 10.06.2024 20:15:14
- Zuletzt bearbeitet 21.11.2024 09:22:08
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a deprecated v4 API example with no log rotation allows denial of service by logging excessive data. Versions 7.14.4 and 8.6.1...