CVE-2021-45898
- EPSS 0.47%
- Veröffentlicht 28.01.2022 17:15:15
- Zuletzt bearbeitet 21.11.2024 06:33:13
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.
CVE-2021-45899
- EPSS 3.2%
- Veröffentlicht 28.01.2022 17:15:15
- Zuletzt bearbeitet 21.11.2024 06:33:13
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
CVE-2021-41597
- EPSS 0.44%
- Veröffentlicht 12.01.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:26:30
SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.
CVE-2021-45903
- EPSS 0.39%
- Veröffentlicht 28.12.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:33:14
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-...
CVE-2021-45041
- EPSS 13.28%
- Veröffentlicht 19.12.2021 09:15:06
- Zuletzt bearbeitet 21.11.2024 06:31:50
SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.
- EPSS 49.11%
- Veröffentlicht 22.10.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:28:12
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because o...
CVE-2021-41595
- EPSS 0.27%
- Veröffentlicht 04.10.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:26:29
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the file_name parameter of the Step3 import functionality.
CVE-2021-41596
- EPSS 0.3%
- Veröffentlicht 04.10.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:26:30
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the RefreshMapping import functionality.
CVE-2021-41869
- EPSS 0.88%
- Veröffentlicht 04.10.2021 07:15:06
- Zuletzt bearbeitet 21.11.2024 06:26:55
SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation.
- EPSS 0.33%
- Veröffentlicht 29.09.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:40
In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with...