Suitecrm · Suitecrm · CVE-2024-36410
**Name of the Vulnerable Software and Affected Versions**
SuiteCRM versions prior to 7.14.4
SuiteCRM versions prior to 8.6.1
**Description**
The issue is related to poor input validation, allowing for SQL Injection in the EmailUIAjax messages count controller. This affects SuiteCRM, an open-source Customer Relationship Management (CRM) software application.
**Recommendations**
For versions prior to 7.14.4, update to version 7.14.4 or later.
For versions prior to 8.6.1, update to version 8.6.1 or later.
As a temporary workaround, consider restricting access to the EmailUIAjax messages count controller until a patch is applied.