PT-2024-26979 · Suitecrm · Suitecrm

Elsicarius

·

Published

2024-06-10

·

Updated

2025-02-17

·

CVE-2024-36412

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SuiteCRM versions prior to 7.14.4 SuiteCRM versions prior to 8.6.1
Description A vulnerability in the events response entry point of SuiteCRM allows for a SQL injection attack. This issue can potentially lead to unauthorized database manipulation.
Recommendations For versions prior to 7.14.4, upgrade to version 7.14.4 or later to resolve the issue. For versions prior to 8.6.1, upgrade to version 8.6.1 or later to resolve the issue.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BIT-SUITECRM-2024-36412
CVE-2024-36412
GHSA-XJX2-38HV-5HH8

Affected Products

Suitecrm