CRITICAL🇵🇱 Wersja polska

CVE-2024-36409

CVSS 9.6v3.1pub. 2024-06-10upd. 2024-11-21

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in Tree data entry point. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

🤖 AI Analysis
How it works

An attacker with an account in the system (authenticated, with low-level permissions) can send a crafted request to the tree data entry point containing malicious SQL code. The lack of proper validation and sanitization of input data causes the injected SQL code to be passed directly to the database engine and executed. The exploit does not require interaction from another user and operates remotely over the network.

Impact

Successful exploitation of this vulnerability may allow an attacker to manipulate data in the database (integrity breach) and disrupt or cause unavailability of the CRM system (availability breach). The scope of the vulnerability extends beyond the application context, indicating potential impact on resources outside the direct control of the application.

Mitigation & patch

SuiteCRM should be updated to version 7.14.4 or later (for the 7.x branch) or to version 8.6.1 or later (for the 8.x branch), which contain the fix for this issue. Detailed information is available in the official security advisory from the vendor on GitHub.

Who is affected

SuiteCRM in versions prior to 7.14.4 and prior to 8.6.1 (both release lines of Salesagility SuiteCRM product).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
  • Salesagility Suitecrm

    APP
    Salesagility
    < 7.14.48.0.0 – 8.6.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2022-50589CRITICAL9.3PL ✓same product

SQL Injection w SuiteCRM umożliwiające zdalne wykonanie kodu (RCE)

CVE-2024-36408CRITICAL9.6PL ✓same product

SQL Injection w kontrolerze Alerts aplikacji SuiteCRM

CVE-2024-36411CRITICAL9.6PL ✓same product

SQL Injection w SuiteCRM — kontroler EmailUIAjax displayView

CVE-2024-36410CRITICAL9.6PL ✓same product

SQL Injection w SuiteCRM — kontroler EmailUIAjax messages count

CVE-2024-36412CRITICAL10.0PL ✓same product

SQL injection w SuiteCRM poprzez punkt wejścia odpowiedzi na zdarzenia