Show filters
86 Total Results
Displaying 61-70 of 86
Sort by:
Attacker Value
Unknown
CVE-2020-28328
Disclosure Date: November 06, 2020 (last updated February 22, 2025)
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.
0
Attacker Value
Unknown
CVE-2019-18782
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism.
0
Attacker Value
Unknown
CVE-2020-8787
Disclosure Date: March 16, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted.
0
Attacker Value
Unknown
CVE-2020-8784
Disclosure Date: March 16, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4).
0
Attacker Value
Unknown
CVE-2020-8785
Disclosure Date: March 16, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4).
0
Attacker Value
Unknown
CVE-2020-8786
Disclosure Date: March 16, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4).
0
Attacker Value
Unknown
CVE-2020-8783
Disclosure Date: March 16, 2020 (last updated February 21, 2025)
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4).
0
Attacker Value
Unknown
CVE-2020-8804
Disclosure Date: February 13, 2020 (last updated February 21, 2025)
SuiteCRM through 7.11.10 allows SQL Injection via the SOAP API, the EmailUIAjax interface, or the MailMerge module.
0
Attacker Value
Unknown
CVE-2020-8800
Disclosure Date: February 13, 2020 (last updated February 21, 2025)
SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.
0
Attacker Value
Unknown
CVE-2020-8803
Disclosure Date: February 13, 2020 (last updated February 21, 2025)
SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.
0