vendor:
SuiteCRM
by:
Mehmet EMIROGLU
5.5
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: SuiteCRM
Affected Version From: 7.10.2007
Affected Version To: 7.10.2007
Patch Exists: NO
Related CWE:
CPE: suitecrm
Platforms Tested: Windows (Wampp)
2019
SuiteCRM 7.10.7 – ‘parentTab’ SQL Vulnerabilities
The SuiteCRM 7.10.7 version is vulnerable to SQL injection attacks. By changing the 'parentTab' parameter to a specific value and appending malicious code to the URL, an attacker can execute arbitrary SQL queries on the database.
Mitigation:
To mitigate this vulnerability, it is recommended to update to the latest version of SuiteCRM.