Show filters
86 Total Results
Displaying 41-50 of 86
Sort by:
Attacker Value
Unknown

CVE-2022-0755

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
Attacker Value
Unknown

CVE-2022-0754

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5.
Attacker Value
Unknown

CVE-2021-45899

Disclosure Date: January 28, 2022 (last updated February 23, 2025)
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
Attacker Value
Unknown

CVE-2021-45898

Disclosure Date: January 28, 2022 (last updated October 07, 2023)
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.
Attacker Value
Unknown

CVE-2021-45897

Disclosure Date: January 28, 2022 (last updated October 07, 2023)
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.
Attacker Value
Unknown

CVE-2021-41597

Disclosure Date: January 12, 2022 (last updated February 23, 2025)
SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.
Attacker Value
Unknown

CVE-2021-45903

Disclosure Date: December 28, 2021 (last updated February 23, 2025)
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268.
Attacker Value
Unknown

CVE-2021-45041

Disclosure Date: December 19, 2021 (last updated February 23, 2025)
SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.
Attacker Value
Unknown

CVE-2021-42840

Disclosure Date: October 22, 2021 (last updated February 23, 2025)
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP file extensions were blocked. NOTE: this issue exists because of an incomplete fix for CVE-2020-28328.
Attacker Value
Unknown

CVE-2021-41596

Disclosure Date: October 04, 2021 (last updated February 23, 2025)
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the RefreshMapping import functionality.