Skip to main content

Vendor archive

salesagility CVEs

Beta · best-effort

105 CVEs tagged to vendor salesagility26 Critical, 41 High, 35 Medium, 3 Low, 0 Unrated.

CVE-2023-5351

Published Oct 3, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3627

Published Jul 11, 2023

Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3293

Published Jun 16, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27474

Published Apr 15, 2022

SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23940

Published Mar 10, 2022

SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP dese…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45899

Published Jan 28, 2022

SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-45898

Published Jan 28, 2022

SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-45897

Published Jan 28, 2022

SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41597

Published Jan 12, 2022

SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45903

Published Dec 28, 2021

A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-45041

Published Dec 19, 2021

SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-42840

Published Oct 22, 2021

SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41596

Published Oct 4, 2021

SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the Re…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41595

Published Oct 4, 2021

SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the file_name parameter of the Ste…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41869

Published Oct 4, 2021

SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25961

Published Sep 29, 2021

In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, whic…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25960

Published Sep 29, 2021

In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). A low privileged attacker can…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39268

Published Aug 18, 2021

Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via malicious SVG files. This occu…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39267

Published Aug 18, 2021

Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via a Content-Type Filter bypass t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-75 of 105 CVEsPage 3 of 5