SQL Injection Vulnerability in SuiteCRM Software by SalesAgility
CVE-2024-36409
8.8HIGH
Summary
SuiteCRM, an open-source Customer Relationship Management software provided by SalesAgility, is vulnerable to SQL Injection in versions prior to 7.14.4 and 8.6.1. The vulnerability stems from inadequate input validation in the Tree data entry point, which could allow unauthorized access to the database, leading to potential data leaks or manipulation. Users of affected versions should upgrade to 7.14.4 or 8.6.1, where the vulnerability has been addressed to enhance security and protect sensitive customer information.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published