PT-2024-26980 · Suitecrm · Suitecrm

Elsicarius

·

Published

2024-06-10

·

Updated

2024-06-12

·

CVE-2024-36413

CVSS v3.1

8.9

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions SuiteCRM versions prior to 7.14.4 SuiteCRM versions prior to 8.6.1
Description A cross-site scripting vulnerability exists in the import module error view of SuiteCRM, allowing for a potential attack. This issue is related to the import module error view.
Recommendations For versions prior to 7.14.4, update to version 7.14.4 or later to resolve the issue. For versions prior to 8.6.1, update to version 8.6.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the import module error view until a patch is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-SUITECRM-2024-36413
CVE-2024-36413
GHSA-PH2C-HVVF-R273

Affected Products

Suitecrm