Show filters
87 Total Results
Displaying 61-70 of 87
Sort by:
Attacker Value
Unknown

CVE-2020-28328

Disclosure Date: November 06, 2020 (last updated February 22, 2025)
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.
Attacker Value
Unknown

CVE-2019-18782

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism.
Attacker Value
Unknown

CVE-2019-18785

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials.
Attacker Value
Unknown

CVE-2020-8787

Disclosure Date: March 16, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted.
Attacker Value
Unknown

CVE-2020-8784

Disclosure Date: March 16, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4).
Attacker Value
Unknown

CVE-2020-8785

Disclosure Date: March 16, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4).
Attacker Value
Unknown

CVE-2020-8786

Disclosure Date: March 16, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4).
Attacker Value
Unknown

CVE-2020-8783

Disclosure Date: March 16, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4).
Attacker Value
Unknown

CVE-2020-8804

Disclosure Date: February 13, 2020 (last updated February 21, 2025)
SuiteCRM through 7.11.10 allows SQL Injection via the SOAP API, the EmailUIAjax interface, or the MailMerge module.
Attacker Value
Unknown

CVE-2020-8800

Disclosure Date: February 13, 2020 (last updated February 21, 2025)
SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.