Remote Code Execution Vulnerability in SuiteCRM by SalesAgility
CVE-2024-36418

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
10 June 2024

Summary

SuiteCRM, a widely-used open-source Customer Relationship Management application, has a vulnerability related to its connectors that permits authenticated users to execute remote code. This issue affects all versions prior to the releases 7.14.4 and 8.6.1, where the vulnerability has been addressed. It is crucial for users operating earlier versions to upgrade promptly to mitigate potential security risks associated with this vulnerability.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-36418 : Remote Code Execution Vulnerability in SuiteCRM by SalesAgility | SecurityVulnerability.io