SuiteCRM v4 API Excessive log data DOS
CVE-2024-36416

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
10 June 2024

Summary

SuiteCRM, an open-source Customer Relationship Management application developed by SalesAgility, has a vulnerability related to a deprecated v4 API example that does not implement log rotation. This flaw allows an attacker to trigger a denial of service condition by causing excessive data logging. The issue affects versions of SuiteCRM prior to 7.14.4 and 8.6.1. Updates released in these versions address the vulnerability, enhancing the software's resilience against such potential attacks.

Affected Version(s)

SuiteCRM < 7.14.4 < 7.14.4

SuiteCRM >= 8.0.0, < 8.6.1 < 8.0.0, 8.6.1

References

EPSS Score

41% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.