SuiteCRM Open-Source CRM Software Vulnerable to File Inclusion Attack
CVE-2024-50333

8.8HIGH

Key Information:

Vendor
Salesagility
Status
Suitecrm
Vendor
CVE Published:
5 November 2024

Summary

SuiteCRM, an open-source Customer Relationship Management software developed by SalesAgility, contains a vulnerability where user input is not properly validated and is written directly to the filesystem. This issue arises from the ParserLabel::addLabels() function, which allows for attacker-controlled data to be written into custom language files included at runtime. This poses a significant security risk as it can lead to unauthorized manipulation of application behavior. The vulnerability has been resolved in versions 7.14.6 and 8.7.1, and users are strongly advised to upgrade to these versions as there are no known workarounds available.

Affected Version(s)

SuiteCRM < 7.14.6 < 7.14.6

SuiteCRM >= 8.0.0, < 8.7.1 < 8.0.0, 8.7.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.