Show filters
87 Total Results
Displaying 31-40 of 87
Sort by:
Attacker Value
Unknown
CVE-2023-6124
Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Server-Side Request Forgery (SSRF) in GitHub repository salesagility/suitecrm prior to 7.14.2, 8.4.2, 7.12.14.
0
Attacker Value
Unknown
CVE-2023-5353
Disclosure Date: October 03, 2023 (last updated October 09, 2023)
Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.
0
Attacker Value
Unknown
CVE-2023-5351
Disclosure Date: October 03, 2023 (last updated October 09, 2023)
Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.
0
Attacker Value
Unknown
CVE-2023-5350
Disclosure Date: October 03, 2023 (last updated October 09, 2023)
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.
0
Attacker Value
Unknown
CVE-2023-3627
Disclosure Date: July 11, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1.
0
Attacker Value
Unknown
CVE-2023-3293
Disclosure Date: June 16, 2023 (last updated October 08, 2023)
Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0.
0
Attacker Value
Unknown
CVE-2023-1034
Disclosure Date: February 25, 2023 (last updated October 08, 2023)
Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.
0
Attacker Value
Unknown
CVE-2022-27474
Disclosure Date: April 15, 2022 (last updated October 07, 2023)
SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field.
0
Attacker Value
Unknown
CVE-2022-23940
Disclosure Date: March 10, 2022 (last updated October 07, 2023)
SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a malicious report, containing a PHP-deserialization payload in the email_recipients field. Once someone accesses this report, the backend will deserialize the content of the email_recipients field and the payload gets executed. Project dependencies include a number of interesting PHP deserialization gadgets (e.g., Monolog/RCE1 from phpggc) that can be used for Code Execution.
0
Attacker Value
Unknown
CVE-2022-0756
Disclosure Date: March 07, 2022 (last updated October 07, 2023)
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
0