CVE-2024-36412

Published Jun 10, 2024

Last updated 5 months ago

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2024-36412 is a vulnerability identified in SuiteCRM, an open-source Customer Relationship Management (CRM) software. Versions of SuiteCRM prior to 7.14.4 and 8.6.1 are susceptible to SQL injection attacks. The vulnerability stems from improper handling of user-supplied input within SQL commands. This flaw allows attackers to execute malicious SQL queries, potentially granting them unauthorized access to sensitive data stored within the SuiteCRM database. The vulnerability is present in the events response entry point of the application. The issue has been addressed in SuiteCRM versions 7.14.4 and 8.6.1.

Description
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for a SQL injection attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
Source
security-advisories@github.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-89
nvd@nist.gov
CWE-89

Social media

Hype score
Not currently trending

Configurations