SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code.
An attacker sends a specially crafted export request, injecting malicious SQL code into the 'uid' parameter without needing to have any account in the system. The application does not properly validate or sanitize this value before passing it to the database query. Successful exploitation of a CWE-89 class vulnerability (SQL injection) leads to privilege escalation at the database level, and as a result to the execution of arbitrary code on the server (RCE).
An unauthenticated attacker can gain full control over the application server through remote code execution of arbitrary code, as well as gain access to all data stored in the database — including customer data and business information.
SuiteCRM should be immediately updated to version 7.12.6 or newer, according to the information in the official release notes from the vendor (https://docs.suitecrm.com/admin/releases/7.12.x/#_7_12_6). Until the patch is implemented, it is recommended to restrict network access to data export functions at the firewall or web server level.
Salesagility SuiteCRM in versions earlier than 7.12.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSalesagility Suitecrm
APPSalesagility< 7.12.6
Related vulnerabilities
SQL Injection w SuiteCRM — kontroler EmailUIAjax displayView
SQL Injection w SuiteCRM — kontroler EmailUIAjax messages count
SQL Injection w kontrolerze Alerts aplikacji SuiteCRM
SQL Injection w SuiteCRM — punkt wejścia danych drzewa
SQL injection w SuiteCRM poprzez punkt wejścia odpowiedzi na zdarzenia