CRITICAL🇵🇱 Wersja polska

CVE-2024-36411

CVSS 9.6v3.1pub. 2024-06-10upd. 2024-11-21

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in EmailUIAjax displayView controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

🤖 AI Analysis
How it works

An authenticated attacker in the application can submit maliciously crafted input data to the EmailUIAjax displayView controller, which is not properly validated or sanitized. This allows injection of arbitrary SQL queries into the database supporting the SuiteCRM application. The attack vector is network-based, requires no user interaction, and does not require elevated privileges.

Impact

An attacker can manipulate data in the database and destroy or modify its contents, which corresponds to high impact on system integrity and availability (I:H, A:H). The exploit can lead to unauthorized modification or deletion of CRM data and disruption of application functionality.

Mitigation & patch

SuiteCRM should be updated to version 7.14.4 or newer (for the 7.x branch) or to version 8.6.1 or newer (for the 8.x branch), which contain the fix for this vulnerability. Details are available in the vendor's GitHub repository.

Who is affected

SuiteCRM in versions earlier than 7.14.4 and earlier than 8.6.1 (Salesagility product)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
  • Salesagility Suitecrm

    APP
    Salesagility
    < 7.14.48.0.0 – 8.6.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2022-50589CRITICAL9.3PL ✓same product

SQL Injection w SuiteCRM umożliwiające zdalne wykonanie kodu (RCE)

CVE-2024-36408CRITICAL9.6PL ✓same product

SQL Injection w kontrolerze Alerts aplikacji SuiteCRM

CVE-2024-36410CRITICAL9.6PL ✓same product

SQL Injection w SuiteCRM — kontroler EmailUIAjax messages count

CVE-2024-36409CRITICAL9.6PL ✓same product

SQL Injection w SuiteCRM — punkt wejścia danych drzewa

CVE-2024-36412CRITICAL10.0PL ✓same product

SQL injection w SuiteCRM poprzez punkt wejścia odpowiedzi na zdarzenia