PT-2024-26985 · Suitecrm · Suitecrm

Anderson7

+1

·

Published

2024-06-10

·

Updated

2024-09-19

·

CVE-2024-36418

CVSS v3.1

8.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SuiteCRM versions prior to 7.14.4 SuiteCRM versions prior to 8.6.1
Description A vulnerability in connectors of SuiteCRM allows an authenticated user to perform a remote code execution attack.
Recommendations For versions prior to 7.14.4, update to version 7.14.4 or later to resolve the issue. For versions prior to 8.6.1, update to version 8.6.1 or later to resolve the issue.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BIT-SUITECRM-2024-36418
CVE-2024-36418
GHSA-MFJ5-37V4-VH5W

Affected Products

Suitecrm