← Back

Salesagility

salesagility

105 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Suitecrm
suitecrm

CVEs (105)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Salesagility
1Suitecrm
Nov 21, 2024
Mar 20, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism.
1Salesagility
1Suitecrm
Nov 21, 2024
Mar 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted.
1Salesagility
1Suitecrm
Nov 21, 2024
Mar 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4).
1Salesagility
1Suitecrm
Nov 21, 2024
Mar 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4).
1Salesagility
1Suitecrm
Nov 21, 2024
Mar 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4).
1Salesagility
1Suitecrm
Nov 21, 2024
Mar 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4).
1Salesagility
1Suitecrm
Nov 21, 2024
Feb 13, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
SuiteCRM through 7.11.10 allows SQL Injection via the SOAP API, the EmailUIAjax interface, or the MailMerge module.
1Salesagility
1Suitecrm
Nov 21, 2024
Feb 13, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.
1Salesagility
1Suitecrm
Nov 21, 2024
Feb 13, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM through 7.11.11 has Incorrect Access Control via action_saveHTMLField Bean Manipulation.
1Salesagility
1Suitecrm
Nov 21, 2024
Feb 13, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SuiteCRM through 7.11.11 allows PHAR Deserialization.
1Salesagility
1Suitecrm
Nov 21, 2024
Feb 13, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.
1Salesagility
1Suitecrm
Nov 21, 2024
Nov 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection.
1Salesagility
1Suitecrm
Nov 21, 2024
Oct 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM 7.11.x and 7.10.x before 7.11.8 and 7.10.20 is vulnerable to vertical privilege escalation.
1Salesagility
1Suitecrm
Nov 21, 2024
Oct 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.
1Salesagility
1Suitecrm
Nov 21, 2024
Sep 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SuiteCRM 7.10.x and 7.11.x before 7.10.20 and 7.11.8 has XSS.
1Salesagility
1Suitecrm
Nov 21, 2024
Sep 27, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allows unintended public exposure of files.
1Salesagility
1Suitecrm
Nov 21, 2024
Jun 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 3 of 3).
1Salesagility
1Suitecrm
Nov 21, 2024
Jun 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3).
1Salesagility
1Suitecrm
Nov 21, 2024
Jun 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection.
1Salesagility
1Suitecrm
Nov 21, 2024
Jun 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3).