SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in EmailUIAjax displayView controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
An authenticated attacker in the application can submit maliciously crafted input data to the EmailUIAjax displayView controller, which is not properly validated or sanitized. This allows injection of arbitrary SQL queries into the database supporting the SuiteCRM application. The attack vector is network-based, requires no user interaction, and does not require elevated privileges.
An attacker can manipulate data in the database and destroy or modify its contents, which corresponds to high impact on system integrity and availability (I:H, A:H). The exploit can lead to unauthorized modification or deletion of CRM data and disruption of application functionality.
SuiteCRM should be updated to version 7.14.4 or newer (for the 7.x branch) or to version 8.6.1 or newer (for the 8.x branch), which contain the fix for this vulnerability. Details are available in the vendor's GitHub repository.
SuiteCRM in versions earlier than 7.14.4 and earlier than 8.6.1 (Salesagility product)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:HSalesagility Suitecrm
APPSalesagility< 7.14.48.0.0 – 8.6.1 (excl.)
Related vulnerabilities
SQL Injection w SuiteCRM umożliwiające zdalne wykonanie kodu (RCE)
SQL Injection w kontrolerze Alerts aplikacji SuiteCRM
SQL Injection w SuiteCRM — kontroler EmailUIAjax messages count
SQL Injection w SuiteCRM — punkt wejścia danych drzewa
SQL injection w SuiteCRM poprzez punkt wejścia odpowiedzi na zdarzenia