SuiteCRM CRM Software Vulnerable to SQL Injection Attack
CVE-2024-49772
8.8HIGH
What is CVE-2024-49772?
SuiteCRM, an open-source customer relationship management application developed by SalesAgility, is impacted by a vulnerability that allows authenticated users with low privileges to execute SQL injection attacks. This weakness stems from inadequate input validation present in SuiteCRM versions 7.14.4. Exploitation of this flaw permits attackers to access and leak sensitive data stored in the database. Users are strongly encouraged to upgrade to versions 7.14.6 or 8.7.1 to mitigate the risk associated with this vulnerability, as there are currently no known workarounds.
Affected Version(s)
SuiteCRM < 7.14.6 < 7.14.6
SuiteCRM >= 8.0.0, < 8.7.1 < 8.0.0, 8.7.1