SQL Injection Vulnerability in SuiteCRM Software by SalesAgility
CVE-2024-36409

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
10 June 2024

Summary

SuiteCRM, an open-source Customer Relationship Management software provided by SalesAgility, is vulnerable to SQL Injection in versions prior to 7.14.4 and 8.6.1. The vulnerability stems from inadequate input validation in the Tree data entry point, which could allow unauthorized access to the database, leading to potential data leaks or manipulation. Users of affected versions should upgrade to 7.14.4 or 8.6.1, where the vulnerability has been addressed to enhance security and protect sensitive customer information.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-36409 : SQL Injection Vulnerability in SuiteCRM Software by SalesAgility | SecurityVulnerability.io