Show filters
86 Total Results
Displaying 21-30 of 86
Sort by:
Attacker Value
Unknown

CVE-2024-36406

Disclosure Date: June 10, 2024 (last updated June 11, 2024)
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, unchecked input allows for open re-direct. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
0
Attacker Value
Unknown

CVE-2024-1644

Disclosure Date: February 20, 2024 (last updated January 06, 2025)
Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI.
Attacker Value
Unknown

CVE-2023-6388

Disclosure Date: February 07, 2024 (last updated February 15, 2024)
Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the application is vulnerable to SSRF.
Attacker Value
Unknown

CVE-2023-47643

Disclosure Date: November 21, 2023 (last updated November 29, 2023)
SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection is enabled without authentication, exposing the scheme defining all object types, arguments, and functions. An attacker can obtain the GraphQL schema and understand the entire attack surface of the API, including sensitive fields such as UserHash. This issue is patched in version 8.4.2. There are no known workarounds.
Attacker Value
Unknown

CVE-2023-6131

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Attacker Value
Unknown

CVE-2023-6130

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Attacker Value
Unknown

CVE-2023-6128

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Attacker Value
Unknown

CVE-2023-6127

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Attacker Value
Unknown

CVE-2023-6126

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Attacker Value
Unknown

CVE-2023-6125

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.