← Back

Salesagility

salesagility

105 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Suitecrm
suitecrm

CVEs (105)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Salesagility
1Suitecrm
Nov 21, 2024
Mar 7, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5.
1Salesagility
1Suitecrm
Nov 21, 2024
Jan 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
1Salesagility
1Suitecrm
Nov 21, 2024
Jan 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.
1Salesagility
1Suitecrm
Nov 21, 2024
Jan 28, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.
1Salesagility
1Suitecrm
Nov 21, 2024
Jan 12, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.
1Salesagility
1Suitecrm
Nov 21, 2024
Dec 28, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a dif...Show more
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268.Show less
1Salesagility
1Suitecrm
Nov 21, 2024
Dec 19, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.
1Salesagility
1Suitecrm
Nov 21, 2024
Oct 22, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file...Show more
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP file extensions were blocked. NOTE: this issue exists because of an incomplete fix for CVE-2020-28328.Show less
1Salesagility
1Suitecrm
Nov 21, 2024
Oct 4, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the RefreshMapping import functionality.
1Salesagility
1Suitecrm
Nov 21, 2024
Oct 4, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the file_name parameter of the Step3 import functionality.
1Salesagility
1Suitecrm
Nov 21, 2024
Oct 4, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation.
1Salesagility
1Suitecrm
Nov 21, 2024
Sep 29, 2021
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover...Show more
In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id.Show less
1Salesagility
1Suitecrm
Nov 21, 2024
Sep 29, 2021
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). A low privileged attacker can use accounts module to inject payloads i...Show more
In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). A low privileged attacker can use accounts module to inject payloads in the input fields. When an administrator access accounts module to export the data as a CSV file and opens it, the payload gets executed. This was not fixed properly as part of CVE-2020-15301, allowing the attacker to bypass the security measure.Show less
1Salesagility
1Suitecrm
Nov 21, 2024
Aug 18, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via malicious SVG files. This occurs because the clean_file_output protecti...Show more
Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via malicious SVG files. This occurs because the clean_file_output protection mechanism can be bypassed.Show less
1Salesagility
1Suitecrm
Nov 21, 2024
Aug 18, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via a Content-Type Filter bypass to upload malicious files. This occurs bec...Show more
Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via a Content-Type Filter bypass to upload malicious files. This occurs because text/html is blocked, but other types that allow JavaScript execution (such as text/xml) are not blocked.Show less
1Salesagility
1Suitecrm
Nov 21, 2024
Apr 30, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field
1Salesagility
1Suitecrm
Nov 21, 2024
Nov 18, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document.
1Salesagility
1Suitecrm
Nov 21, 2024
Nov 18, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.
1Salesagility
1Suitecrm
Nov 21, 2024
Nov 18, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.
1Salesagility
1Suitecrm
Nov 21, 2024
Nov 6, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlle...Show more
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.Show less