CRITICAL🇵🇱 Wersja polska

CVE-2024-36408

CVSS 9.6v3.1pub. 2024-06-10upd. 2024-11-21

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in the `Alerts` controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

🤖 AI Analysis
How it works

Improper input validation in the `Alerts` controller allows an authenticated attacker to inject malicious SQL queries. Through a properly crafted network request, it is possible to pass untrusted data directly to the database layer without proper sanitization or parameterization. The vulnerability is remotely exploitable without requiring user interaction, which significantly lowers the threshold for its exploitation.

Impact

An attacker can manipulate data in the database (high integrity) and cause disruptions to CRM system availability (high availability). Due to the changed scope (S:C), the impact may extend beyond the directly vulnerable application.

Mitigation & patch

SuiteCRM should be updated to version 7.14.4 or 8.6.1, which contain a patch eliminating this vulnerability. Details are available in the official security advisory from the vendor.

Who is affected

SuiteCRM in versions earlier than 7.14.4 and earlier than 8.6.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
  • Salesagility Suitecrm

    APP
    Salesagility
    < 7.14.48.0.0 – 8.6.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2022-50589CRITICAL9.3PL ✓same product

SQL Injection w SuiteCRM umożliwiające zdalne wykonanie kodu (RCE)

CVE-2024-36409CRITICAL9.6PL ✓same product

SQL Injection w SuiteCRM — punkt wejścia danych drzewa

CVE-2024-36411CRITICAL9.6PL ✓same product

SQL Injection w SuiteCRM — kontroler EmailUIAjax displayView

CVE-2024-36410CRITICAL9.6PL ✓same product

SQL Injection w SuiteCRM — kontroler EmailUIAjax messages count

CVE-2024-36412CRITICAL10.0PL ✓same product

SQL injection w SuiteCRM poprzez punkt wejścia odpowiedzi na zdarzenia