Product:

Suitecrm

(Salesagility)
Repositories https://github.com/salesagility/SuiteCRM
#Vulnerabilities 85
Date Id Summary Products Score Patch Annotated
2021-12-28 CVE-2021-45903 A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268. Suitecrm 6.1
2022-01-12 CVE-2021-41597 SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive. Suitecrm 8.8
2022-01-28 CVE-2021-45897 SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution. Suitecrm 8.8
2022-01-28 CVE-2021-45898 SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion. Suitecrm 9.8
2022-01-28 CVE-2021-45899 SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution. Suitecrm 9.8
2022-03-07 CVE-2022-0754 SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5. Suitecrm 6.5
2022-03-07 CVE-2022-0755 Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5. Suitecrm 4.3
2022-03-07 CVE-2022-0756 Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5. Suitecrm 6.5
2022-03-10 CVE-2022-23940 SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a malicious report, containing a PHP-deserialization payload in the email_recipients field. Once someone accesses this report, the backend will deserialize the content of the email_recipients field and the payload gets... Suitecrm 8.8
2022-04-15 CVE-2022-27474 SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field. Suitecrm 7.2