漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
SuiteCRM: Authenticated SQL Injection Possible in Reschedule Call Module
Vulnerability Description
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.7 and below and 8.0.0-beta.1 through 8.9.0 8.0.0-beta.1, an attacker can craft a malicious call_id that alters the logic of the SQL query or injects arbitrary SQL. An attack can lead to unauthorized data access and data ex-filtration, complete database compromise, and other various issues. This issue is fixed in versions 7.14.8 and 8.9.1.
CVSS Information
N/A
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
SuiteCRM SQL注入漏洞
Vulnerability Description
SuiteCRM是SuiteCRM团队的一个客户关系管理系统。 SuiteCRM 7.14.7及之前版本和8.0.0-beta.1至8.9.0版本存在SQL注入漏洞,该漏洞源于攻击者可构造恶意call_id参数操纵SQL查询逻辑或注入任意SQL语句,可能导致未经授权的数据访问、数据渗漏和完整数据库泄露。
CVSS Information
N/A
Vulnerability Type
N/A