SuiteCRM是SuiteCRM团队的一个客户关系管理系统。 SuiteCRM存在输入验证错误漏洞。攻击者利用该漏洞可以绕过某些检查。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| salesagility | SuiteCRM | < 7.14.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-49772 | 8.8 HIGH | Authenticated SQL injection in AM_ProjectTemplates controller in SuiteCRM |
| CVE-2024-50332 | 8.8 HIGH | Authenticated Blind SQL Injection in DeleteRelationShip in SuiteCRM |
| CVE-2024-50333 | 6.6 MEDIUM | RCE in ModuleBuilder in SuiteCRM |
| CVE-2024-49773 | 5.3 MEDIUM | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Su |
| CVE-2024-50335 | 4.9 MEDIUM | Authenticated XSS in "Publish Key" Field Allowing Unauthorized Administrator User Creation |
No comments yet