Vulnerabilities > Salesagility > Suitecrm > 7.7.7

DATE CVE VULNERABILITY TITLE RISK
2023-07-11 CVE-2023-3627 Cross-Site Request Forgery (CSRF) vulnerability in Salesagility Suitecrm
Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1.
network
low complexity
salesagility CWE-352
8.8
2023-02-25 CVE-2023-1034 Unspecified vulnerability in Salesagility Suitecrm
Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.
network
low complexity
salesagility
8.8
2022-03-10 CVE-2022-23940 Deserialization of Untrusted Data vulnerability in Salesagility Suitecrm
SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution.
network
low complexity
salesagility CWE-502
8.8
2022-03-07 CVE-2022-0754 SQL Injection vulnerability in Salesagility Suitecrm
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5.
network
low complexity
salesagility CWE-89
6.5
2022-03-07 CVE-2022-0755 Unspecified vulnerability in Salesagility Suitecrm
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
network
low complexity
salesagility
4.3
2022-03-07 CVE-2022-0756 Unspecified vulnerability in Salesagility Suitecrm
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
network
low complexity
salesagility
6.5
2022-01-28 CVE-2021-45897 Unspecified vulnerability in Salesagility Suitecrm
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.
network
low complexity
salesagility
8.8
2022-01-28 CVE-2021-45898 Unspecified vulnerability in Salesagility Suitecrm
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.
network
low complexity
salesagility
critical
9.8
2022-01-28 CVE-2021-45899 Deserialization of Untrusted Data vulnerability in Salesagility Suitecrm
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
network
low complexity
salesagility CWE-502
critical
9.8
2021-12-28 CVE-2021-45903 Cross-site Scripting vulnerability in Salesagility Suitecrm
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268.
network
low complexity
salesagility CWE-79
6.1