Description
SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 7.12.6
Timeline
| 2022-06-09: | Exodus Intelligence publicly discloses technical details of vulnerability. |
| 2022-05-24: | SuiteCRM releases patched version - 7.12.6. |
Credits
Exodus Intelligence
References
docs.suitecrm.com/admin/releases/7.12.x/
blog.exodusintel.com/...request-sql-injection-vulnerability/
www.vulncheck.com/.../suitecrm-sqli-via-export-functionality