Vulnerabilities > Salesagility

DATE CVE VULNERABILITY TITLE RISK
2022-04-15 CVE-2022-27474 Unspecified vulnerability in Salesagility Suitecrm 7.11.23
SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field.
network
low complexity
salesagility
6.5
2022-03-10 CVE-2022-23940 Deserialization of Untrusted Data vulnerability in Salesagility Suitecrm
SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution.
network
low complexity
salesagility CWE-502
6.5
2022-03-07 CVE-2022-0754 SQL Injection vulnerability in Salesagility Suitecrm
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5.
network
low complexity
salesagility CWE-89
4.0
2022-03-07 CVE-2022-0755 Improper Authentication vulnerability in Salesagility Suitecrm
Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.12.5.
network
low complexity
salesagility CWE-287
4.0
2022-03-07 CVE-2022-0756 Incorrect Authorization vulnerability in Salesagility Suitecrm
Improper Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
network
low complexity
salesagility CWE-863
4.0
2022-01-28 CVE-2021-45897 Unspecified vulnerability in Salesagility Suitecrm
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.
network
low complexity
salesagility
6.5
2022-01-28 CVE-2021-45898 Unspecified vulnerability in Salesagility Suitecrm
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.
network
low complexity
salesagility
7.5
2022-01-28 CVE-2021-45899 Deserialization of Untrusted Data vulnerability in Salesagility Suitecrm
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
network
low complexity
salesagility CWE-502
7.5
2022-01-12 CVE-2021-41597 Cross-Site Request Forgery (CSRF) vulnerability in Salesagility Suitecrm
SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.
6.8
2021-12-28 CVE-2021-45903 Cross-site Scripting vulnerability in Salesagility Suitecrm
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268.
4.3