Show filters
87 Total Results
Displaying 71-80 of 87
Sort by:
Attacker Value
Unknown

CVE-2020-8803

Disclosure Date: February 13, 2020 (last updated February 21, 2025)
SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.
Attacker Value
Unknown

CVE-2020-8802

Disclosure Date: February 13, 2020 (last updated February 21, 2025)
SuiteCRM through 7.11.11 has Incorrect Access Control via action_saveHTMLField Bean Manipulation.
Attacker Value
Unknown

CVE-2020-8801

Disclosure Date: February 13, 2020 (last updated February 21, 2025)
SuiteCRM through 7.11.11 allows PHAR Deserialization.
Attacker Value
Unknown

CVE-2019-18784

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection.
Attacker Value
Unknown

CVE-2019-14454

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
SuiteCRM 7.11.x and 7.10.x before 7.11.8 and 7.10.20 is vulnerable to vertical privilege escalation.
Attacker Value
Unknown

CVE-2019-13335

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.
Attacker Value
Unknown

CVE-2019-14752

Disclosure Date: September 30, 2019 (last updated November 27, 2024)
SuiteCRM 7.10.x and 7.11.x before 7.10.20 and 7.11.8 has XSS.
Attacker Value
Unknown

CVE-2019-16922

Disclosure Date: September 27, 2019 (last updated November 27, 2024)
SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allows unintended public exposure of files.
Attacker Value
Unknown

CVE-2019-12599

Disclosure Date: June 07, 2019 (last updated November 27, 2024)
SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection.
0
Attacker Value
Unknown

CVE-2019-12598

Disclosure Date: June 07, 2019 (last updated November 27, 2024)
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3).
0