SuiteCRM CRM Software Vulnerable to SQL Injection Attack
CVE-2024-49772
8.8HIGH
Key Information:
- Vendor
- Salesagility
- Status
- Suitecrm
- Vendor
- CVE Published:
- 5 November 2024
Summary
SuiteCRM, an open-source customer relationship management application developed by SalesAgility, is impacted by a vulnerability that allows authenticated users with low privileges to execute SQL injection attacks. This weakness stems from inadequate input validation present in SuiteCRM versions 7.14.4. Exploitation of this flaw permits attackers to access and leak sensitive data stored in the database. Users are strongly encouraged to upgrade to versions 7.14.6 or 8.7.1 to mitigate the risk associated with this vulnerability, as there are currently no known workarounds.
Affected Version(s)
SuiteCRM < 7.14.6 < 7.14.6
SuiteCRM >= 8.0.0, < 8.7.1 < 8.0.0, 8.7.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved