SuiteCRM v4 API Excessive log data DOS
CVE-2024-36416
8.6HIGH
Summary
SuiteCRM, an open-source Customer Relationship Management application developed by SalesAgility, has a vulnerability related to a deprecated v4 API example that does not implement log rotation. This flaw allows an attacker to trigger a denial of service condition by causing excessive data logging. The issue affects versions of SuiteCRM prior to 7.14.4 and 8.6.1. Updates released in these versions address the vulnerability, enhancing the software's resilience against such potential attacks.
Affected Version(s)
SuiteCRM < 7.14.4 < 7.14.4
SuiteCRM >= 8.0.0, < 8.6.1 < 8.0.0, 8.6.1
References
EPSS Score
41% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published