CRITICAL🇵🇱 Wersja polska

CVE-2024-36410

CVSS 9.6v3.1pub. 2024-06-10upd. 2024-11-21

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in EmailUIAjax messages count controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

🤖 AI Analysis
How it works

An attacker with an account in the system can submit crafted input data to the EmailUIAjax controller responsible for message counting. Due to lack of proper validation, this data is passed directly to SQL queries, enabling manipulation. The exploit does not require user interaction or special privileges beyond basic authentication, and its scope extends beyond the direct application context (Scope: Changed).

Impact

An attacker can manipulate data in the database (integrity violation) and cause system or data unavailability (availability violation). The vulnerability does not directly allow reading confidential data under the CVSS model, however data writing and destruction constitute a serious operational threat.

Mitigation & patch

SuiteCRM should be updated to version 7.14.4 or 8.6.1, which contain a patch eliminating the described vulnerability. Details available in the official security advisory on GitHub Salesagility.

Who is affected

SuiteCRM in versions earlier than 7.14.4 and earlier than 8.6.1 (Salesagility production).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
  • Salesagility Suitecrm

    APP
    Salesagility
    < 7.14.48.0.0 – 8.6.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2022-50589CRITICAL9.3PL ✓same product

SQL Injection w SuiteCRM umożliwiające zdalne wykonanie kodu (RCE)

CVE-2024-36408CRITICAL9.6PL ✓same product

SQL Injection w kontrolerze Alerts aplikacji SuiteCRM

CVE-2024-36411CRITICAL9.6PL ✓same product

SQL Injection w SuiteCRM — kontroler EmailUIAjax displayView

CVE-2024-36409CRITICAL9.6PL ✓same product

SQL Injection w SuiteCRM — punkt wejścia danych drzewa

CVE-2024-36412CRITICAL10.0PL ✓same product

SQL injection w SuiteCRM poprzez punkt wejścia odpowiedzi na zdarzenia