PT-2026-26452 · Suitecrm · Suitecrm
Guilhermemury
·
Publicado
2026-03-19
·
Atualizado
2026-03-20
·
CVE-2026-33289
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SuiteCRM versions prior to 7.15.1
SuiteCRM versions prior to 8.9.3
Description
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A flaw exists in the authentication process where the application does not properly validate user-provided input before including it in the LDAP search filter. An attacker can inject LDAP control characters to manipulate the query logic, potentially leading to authentication bypass or information disclosure. The
LDAP search filter is vulnerable to manipulation through injected control characters. The vulnerable component is the authentication flow.Recommendations
Versions prior to 7.15.1 should be updated to version 7.15.1 or later.
Versions prior to 8.9.3 should be updated to version 8.9.3 or later.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Suitecrm