PT-2026-26446 · Suitecrm · Suitecrm
Jbince
·
Publicado
2026-03-19
·
Atualizado
2026-03-20
·
CVE-2026-29108
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SuiteCRM versions prior to 8.9.3
Description
SuiteCRM is a customer relationship management software application. An authenticated API endpoint allows any user to retrieve detailed information about any other user, including their password hash, username, and multi-factor authentication (MFA) configuration. Because any authenticated user can query this endpoint, it is possible to retrieve and potentially crack the passwords of administrative users. The vulnerable API endpoint allows unauthorized access to sensitive user data.
Recommendations
Update to version 8.9.3 or later.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Suitecrm