Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2023-47643

Disclosure Date: November 21, 2023 (last updated November 29, 2023)
SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection is enabled without authentication, exposing the scheme defining all object types, arguments, and functions. An attacker can obtain the GraphQL schema and understand the entire attack surface of the API, including sensitive fields such as UserHash. This issue is patched in version 8.4.2. There are no known workarounds.
Attacker Value
Unknown

CVE-2023-6131

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Attacker Value
Unknown

CVE-2023-6130

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Attacker Value
Unknown

CVE-2023-6128

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Attacker Value
Unknown

CVE-2023-6127

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Attacker Value
Unknown

CVE-2023-6126

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Attacker Value
Unknown

CVE-2023-6125

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Attacker Value
Unknown

CVE-2023-6124

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Server-Side Request Forgery (SSRF) in GitHub repository salesagility/suitecrm prior to 7.14.2, 8.4.2, 7.12.14.