Remote Code Execution Vulnerability in SuiteCRM by SalesAgility
CVE-2024-36418
8.8HIGH
Summary
SuiteCRM, a widely-used open-source Customer Relationship Management application, has a vulnerability related to its connectors that permits authenticated users to execute remote code. This issue affects all versions prior to the releases 7.14.4 and 8.6.1, where the vulnerability has been addressed. It is crucial for users operating earlier versions to upgrade promptly to mitigate potential security risks associated with this vulnerability.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published