SuiteCRM CRM Software Vulnerable to SQL Injection Attack
CVE-2024-49772
What is CVE-2024-49772?
SuiteCRM, an open-source customer relationship management application developed by SalesAgility, is impacted by a vulnerability that allows authenticated users with low privileges to execute SQL injection attacks. This weakness stems from inadequate input validation present in SuiteCRM versions 7.14.4. Exploitation of this flaw permits attackers to access and leak sensitive data stored in the database. Users are strongly encouraged to upgrade to versions 7.14.6 or 8.7.1 to mitigate the risk associated with this vulnerability, as there are currently no known workarounds.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SuiteCRM < 7.14.6 < 7.14.6
SuiteCRM >= 8.0.0, < 8.7.1 < 8.0.0, 8.7.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
