PT-2023-30531 · Suitecrm · Suitecrm

X3419

·

Publicado

2023-11-21

·

Atualizado

2024-03-06

·

CVE-2023-47643

CVSS v3.1

3.1

Baixa

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SuiteCRM versions prior to 8.4.2
Description The issue affects SuiteCRM, a Customer Relationship Management (CRM) software application, where Graphql Introspection is enabled without authentication. This exposes the scheme defining all object types, arguments, and functions, allowing an attacker to obtain the GraphQL schema and understand the entire attack surface of the API. Sensitive fields, such as UserHash, are included in this exposure.
Recommendations For versions prior to 8.4.2, update to version 8.4.2 to resolve the issue. As a temporary workaround, consider disabling Graphql Introspection until the update can be applied.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-SUITECRM-2023-47643
CVE-2023-47643
GHSA-FXWW-JQFV-9RRR

Produtos afetados

Suitecrm