PT-2020-20293 · Salesagility · Suitecrm

Egidio Romano

·

Published

2020-02-13

·

Updated

2024-03-06

·

CVE-2020-8804

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SuiteCRM versions prior to 7.11.11
Description The issue allows SQL Injection via the SOAP API, the EmailUIAjax interface, or the MailMerge module.
Recommendations For versions prior to 7.11.11, update to version 7.11.11 or later to resolve the issue.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BIT-SUITECRM-2020-8804
CVE-2020-8804

Affected Products

Suitecrm