SuiteCRM Open-Source CRM Software Vulnerable to File Inclusion Attack
CVE-2024-50333
What is CVE-2024-50333?
SuiteCRM, an open-source Customer Relationship Management software developed by SalesAgility, contains a vulnerability where user input is not properly validated and is written directly to the filesystem. This issue arises from the ParserLabel::addLabels() function, which allows for attacker-controlled data to be written into custom language files included at runtime. This poses a significant security risk as it can lead to unauthorized manipulation of application behavior. The vulnerability has been resolved in versions 7.14.6 and 8.7.1, and users are strongly advised to upgrade to these versions as there are no known workarounds available.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SuiteCRM < 7.14.6 < 7.14.6
SuiteCRM >= 8.0.0, < 8.7.1 < 8.0.0, 8.7.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
