Vulnerabilities > Salesagility > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-01-12 | CVE-2021-41597 | Cross-Site Request Forgery (CSRF) vulnerability in Salesagility Suitecrm SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive. | 8.8 |
2021-12-19 | CVE-2021-45041 | SQL Injection vulnerability in Salesagility Suitecrm SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date. | 8.8 |
2021-10-22 | CVE-2021-42840 | Unrestricted Upload of File with Dangerous Type vulnerability in Salesagility Suitecrm SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. | 8.8 |
2021-10-04 | CVE-2021-41869 | Unspecified vulnerability in Salesagility Suitecrm SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation. | 8.8 |
2021-09-29 | CVE-2021-25960 | Improper Neutralization of Formula Elements in a CSV File vulnerability in Salesagility Suitecrm In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). | 8.0 |
2021-09-29 | CVE-2021-25961 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Salesagility Suitecrm In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id. | 8.0 |
2020-11-18 | CVE-2020-15301 | Improper Neutralization of Formula Elements in a CSV File vulnerability in Salesagility Suitecrm SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. | 7.8 |
2020-11-06 | CVE-2020-28328 | Unrestricted Upload of File with Dangerous Type vulnerability in Salesagility Suitecrm SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. | 8.8 |
2020-03-16 | CVE-2020-8787 | Improper Input Validation vulnerability in Salesagility Suitecrm SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted. | 7.5 |
2020-02-13 | CVE-2020-8801 | Deserialization of Untrusted Data vulnerability in Salesagility Suitecrm SuiteCRM through 7.11.11 allows PHAR Deserialization. | 7.2 |