CVE-2024-49773
- EPSS 0.3%
- Veröffentlicht 05.11.2024 19:15:06
- Zuletzt bearbeitet 13.11.2024 20:29:11
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Poor input validation in export allows authenticated user do a SQL injection attack. User-controlled input is used to build SQL query. `current_...
CVE-2024-49774
- EPSS 0.49%
- Veröffentlicht 05.11.2024 19:15:06
- Zuletzt bearbeitet 13.11.2024 20:40:26
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM relies on the blacklist of functions/methods to prevent installation of malicious MLPs. But this checks can be bypassed with some synta...
CVE-2024-50332
- EPSS 0.43%
- Veröffentlicht 05.11.2024 19:15:06
- Zuletzt bearbeitet 13.11.2024 18:59:49
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Insufficient input value validation causes Blind SQL injection in DeleteRelationShip. This issue has been addressed in versions 7.14.6 and 8.7.1...
CVE-2024-50333
- EPSS 0.39%
- Veröffentlicht 05.11.2024 19:15:06
- Zuletzt bearbeitet 13.11.2024 20:10:45
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. User input is not validated and is written to the filesystem. The ParserLabel::addLabels() function can be used to write attacker-controlled dat...
CVE-2024-49772
- EPSS 0.43%
- Veröffentlicht 05.11.2024 19:15:05
- Zuletzt bearbeitet 13.11.2024 20:19:54
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In SuiteCRM versions 7.14.4, poor input validation allows authenticated user do a SQL injection attack. Authenticated user with low pivilege can...
CVE-2024-45392
- EPSS 0.28%
- Veröffentlicht 05.09.2024 17:15:12
- Zuletzt bearbeitet 06.09.2024 13:24:34
SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Versions 7.14.5 and 8.6.2 contain a patch for the issu...
CVE-2024-36419
- EPSS 0.24%
- Veröffentlicht 10.06.2024 22:15:11
- Zuletzt bearbeitet 21.11.2024 09:22:08
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prior to 8.6.1 allows for Host Header Injection when directly accessing the `/legacy` route. Version 8.6.1 contains a patch for the is...
CVE-2024-36418
- EPSS 0.8%
- Veröffentlicht 10.06.2024 21:15:52
- Zuletzt bearbeitet 21.11.2024 09:22:08
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in connectors allows an authenticated user to perform a remote code execution attack. Versions 7.14.4 and 8.6....
CVE-2024-36413
- EPSS 0.31%
- Veröffentlicht 10.06.2024 20:15:14
- Zuletzt bearbeitet 21.11.2024 09:22:07
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in the import module error view allows for a cross-site scripting attack. Versions 7.14.4 and 8.6.1 contain a ...
CVE-2024-36414
- EPSS 0.36%
- Veröffentlicht 10.06.2024 20:15:14
- Zuletzt bearbeitet 21.11.2024 09:22:07
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in the connectors file verification allows for a server-side request forgery attack. Versions 7.14.4 and 8.6.1...