SuiteCRM是SuiteCRM团队的一个客户关系管理系统。 SuiteCRM 7.14.4版本存在SQL注入漏洞,该漏洞源于输入验证不充分。攻击者利用该漏洞可以泄露数据库中的所有数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| salesagility | SuiteCRM | < 7.14.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-50332 | 8.8 HIGH | Authenticated Blind SQL Injection in DeleteRelationShip in SuiteCRM |
| CVE-2024-49774 | 7.2 HIGH | ModuleScanner flaws in SuiteCRM |
| CVE-2024-50333 | 6.6 MEDIUM | RCE in ModuleBuilder in SuiteCRM |
| CVE-2024-49773 | 5.3 MEDIUM | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Su |
| CVE-2024-50335 | 4.9 MEDIUM | Authenticated XSS in "Publish Key" Field Allowing Unauthorized Administrator User Creation |
No comments yet