Vulnerabilities > Salesagility > High

DATE CVE VULNERABILITY TITLE RISK
2022-01-12 CVE-2021-41597 Cross-Site Request Forgery (CSRF) vulnerability in Salesagility Suitecrm
SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.
network
low complexity
salesagility CWE-352
8.8
2021-12-19 CVE-2021-45041 SQL Injection vulnerability in Salesagility Suitecrm
SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.
network
low complexity
salesagility CWE-89
8.8
2021-10-22 CVE-2021-42840 Unrestricted Upload of File with Dangerous Type vulnerability in Salesagility Suitecrm
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting.
network
low complexity
salesagility CWE-434
8.8
2021-10-04 CVE-2021-41869 Unspecified vulnerability in Salesagility Suitecrm
SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation.
network
low complexity
salesagility
8.8
2021-09-29 CVE-2021-25960 Improper Neutralization of Formula Elements in a CSV File vulnerability in Salesagility Suitecrm
In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection).
network
low complexity
salesagility CWE-1236
8.0
2021-09-29 CVE-2021-25961 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Salesagility Suitecrm
In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id.
network
low complexity
salesagility CWE-640
8.0
2020-11-18 CVE-2020-15301 Improper Neutralization of Formula Elements in a CSV File vulnerability in Salesagility Suitecrm
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules.
local
low complexity
salesagility CWE-1236
7.8
2020-11-06 CVE-2020-28328 Unrestricted Upload of File with Dangerous Type vulnerability in Salesagility Suitecrm
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting.
network
low complexity
salesagility CWE-434
8.8
2020-03-16 CVE-2020-8787 Improper Input Validation vulnerability in Salesagility Suitecrm
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted.
network
low complexity
salesagility CWE-20
7.5
2020-02-13 CVE-2020-8801 Deserialization of Untrusted Data vulnerability in Salesagility Suitecrm
SuiteCRM through 7.11.11 allows PHAR Deserialization.
network
low complexity
salesagility CWE-502
7.2