SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in Tree data entry point. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
An attacker with an account in the system (authenticated, with low-level permissions) can send a crafted request to the tree data entry point containing malicious SQL code. The lack of proper validation and sanitization of input data causes the injected SQL code to be passed directly to the database engine and executed. The exploit does not require interaction from another user and operates remotely over the network.
Successful exploitation of this vulnerability may allow an attacker to manipulate data in the database (integrity breach) and disrupt or cause unavailability of the CRM system (availability breach). The scope of the vulnerability extends beyond the application context, indicating potential impact on resources outside the direct control of the application.
SuiteCRM should be updated to version 7.14.4 or later (for the 7.x branch) or to version 8.6.1 or later (for the 8.x branch), which contain the fix for this issue. Detailed information is available in the official security advisory from the vendor on GitHub.
SuiteCRM in versions prior to 7.14.4 and prior to 8.6.1 (both release lines of Salesagility SuiteCRM product).
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:HSalesagility Suitecrm
APPSalesagility< 7.14.48.0.0 – 8.6.1 (excl.)
Related vulnerabilities
SQL Injection w SuiteCRM umożliwiające zdalne wykonanie kodu (RCE)
SQL Injection w kontrolerze Alerts aplikacji SuiteCRM
SQL Injection w SuiteCRM — kontroler EmailUIAjax displayView
SQL Injection w SuiteCRM — kontroler EmailUIAjax messages count
SQL injection w SuiteCRM poprzez punkt wejścia odpowiedzi na zdarzenia