SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in the `Alerts` controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
Improper input validation in the `Alerts` controller allows an authenticated attacker to inject malicious SQL queries. Through a properly crafted network request, it is possible to pass untrusted data directly to the database layer without proper sanitization or parameterization. The vulnerability is remotely exploitable without requiring user interaction, which significantly lowers the threshold for its exploitation.
An attacker can manipulate data in the database (high integrity) and cause disruptions to CRM system availability (high availability). Due to the changed scope (S:C), the impact may extend beyond the directly vulnerable application.
SuiteCRM should be updated to version 7.14.4 or 8.6.1, which contain a patch eliminating this vulnerability. Details are available in the official security advisory from the vendor.
SuiteCRM in versions earlier than 7.14.4 and earlier than 8.6.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:HSalesagility Suitecrm
APPSalesagility< 7.14.48.0.0 – 8.6.1 (excl.)
Related vulnerabilities
SQL Injection w SuiteCRM umożliwiające zdalne wykonanie kodu (RCE)
SQL Injection w SuiteCRM — punkt wejścia danych drzewa
SQL Injection w SuiteCRM — kontroler EmailUIAjax displayView
SQL Injection w SuiteCRM — kontroler EmailUIAjax messages count
SQL injection w SuiteCRM poprzez punkt wejścia odpowiedzi na zdarzenia