SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in EmailUIAjax messages count controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
An attacker with an account in the system can submit crafted input data to the EmailUIAjax controller responsible for message counting. Due to lack of proper validation, this data is passed directly to SQL queries, enabling manipulation. The exploit does not require user interaction or special privileges beyond basic authentication, and its scope extends beyond the direct application context (Scope: Changed).
An attacker can manipulate data in the database (integrity violation) and cause system or data unavailability (availability violation). The vulnerability does not directly allow reading confidential data under the CVSS model, however data writing and destruction constitute a serious operational threat.
SuiteCRM should be updated to version 7.14.4 or 8.6.1, which contain a patch eliminating the described vulnerability. Details available in the official security advisory on GitHub Salesagility.
SuiteCRM in versions earlier than 7.14.4 and earlier than 8.6.1 (Salesagility production).
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:HSalesagility Suitecrm
APPSalesagility< 7.14.48.0.0 – 8.6.1 (excl.)
Related vulnerabilities
SQL Injection w SuiteCRM umożliwiające zdalne wykonanie kodu (RCE)
SQL Injection w kontrolerze Alerts aplikacji SuiteCRM
SQL Injection w SuiteCRM — kontroler EmailUIAjax displayView
SQL Injection w SuiteCRM — punkt wejścia danych drzewa
SQL injection w SuiteCRM poprzez punkt wejścia odpowiedzi na zdarzenia