Show filters
87 Total Results
Displaying 31-40 of 87
Sort by:
Attacker Value
Unknown

CVE-2023-6124

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Server-Side Request Forgery (SSRF) in GitHub repository salesagility/suitecrm prior to 7.14.2, 8.4.2, 7.12.14.
Attacker Value
Unknown

CVE-2023-5353

Disclosure Date: October 03, 2023 (last updated October 09, 2023)
Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.
Attacker Value
Unknown

CVE-2023-5351

Disclosure Date: October 03, 2023 (last updated October 09, 2023)
Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.
Attacker Value
Unknown

CVE-2023-5350

Disclosure Date: October 03, 2023 (last updated October 09, 2023)
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.
Attacker Value
Unknown

CVE-2023-3627

Disclosure Date: July 11, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1.
Attacker Value
Unknown

CVE-2023-3293

Disclosure Date: June 16, 2023 (last updated October 08, 2023)
Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0.
Attacker Value
Unknown

CVE-2023-1034

Disclosure Date: February 25, 2023 (last updated October 08, 2023)
Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.
Attacker Value
Unknown

CVE-2022-27474

Disclosure Date: April 15, 2022 (last updated October 07, 2023)
SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field.
Attacker Value
Unknown

CVE-2022-23940

Disclosure Date: March 10, 2022 (last updated October 07, 2023)
SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a malicious report, containing a PHP-deserialization payload in the email_recipients field. Once someone accesses this report, the backend will deserialize the content of the email_recipients field and the payload gets executed. Project dependencies include a number of interesting PHP deserialization gadgets (e.g., Monolog/RCE1 from phpggc) that can be used for Code Execution.
Attacker Value
Unknown

CVE-2022-0756

Disclosure Date: March 07, 2022 (last updated October 07, 2023)
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.