PT-2024-34146 · Suitecrm · Suitecrm

Dzentota

·

Published

2024-11-05

·

Updated

2025-09-03

·

CVE-2024-50333

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SuiteCRM versions prior to 7.14.6 SuiteCRM versions prior to 8.7.1
Description: The issue arises from the lack of validation of user input, which is then written to the filesystem. The ParserLabel::addLabels() function can be exploited to write attacker-controlled data into custom language files that are included at runtime.
Recommendations: For versions prior to 7.14.6, upgrade to version 7.14.6 or later. For versions prior to 8.7.1, upgrade to version 8.7.1 or later. As a temporary workaround, consider restricting access to the ParserLabel::addLabels() function until a patch is available.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BIT-SUITECRM-2024-50333
CVE-2024-50333
GHSA-QRV6-3Q86-QV89

Affected Products

Suitecrm