CRM System Vulnerability: Deletion of Records via API
CVE-2024-45392
4.3MEDIUM
Key Information:
- Vendor
- SuiteCRM
- Status
- Suitecrm
- Vendor
- CVE Published:
- 5 September 2024
Summary
SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Versions 7.14.5 and 8.6.2 contain a patch for the issue.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published