Show filters
86 Total Results
Displaying 61-70 of 86
Sort by:
Attacker Value
Unknown

CVE-2020-28328

Disclosure Date: November 06, 2020 (last updated February 22, 2025)
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.
Attacker Value
Unknown

CVE-2019-18782

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism.
Attacker Value
Unknown

CVE-2020-8787

Disclosure Date: March 16, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted.
Attacker Value
Unknown

CVE-2020-8784

Disclosure Date: March 16, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4).
Attacker Value
Unknown

CVE-2020-8785

Disclosure Date: March 16, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4).
Attacker Value
Unknown

CVE-2020-8786

Disclosure Date: March 16, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4).
Attacker Value
Unknown

CVE-2020-8783

Disclosure Date: March 16, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4).
Attacker Value
Unknown

CVE-2020-8804

Disclosure Date: February 13, 2020 (last updated February 21, 2025)
SuiteCRM through 7.11.10 allows SQL Injection via the SOAP API, the EmailUIAjax interface, or the MailMerge module.
Attacker Value
Unknown

CVE-2020-8800

Disclosure Date: February 13, 2020 (last updated February 21, 2025)
SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.
Attacker Value
Unknown

CVE-2020-8803

Disclosure Date: February 13, 2020 (last updated February 21, 2025)
SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.