CVE-2020-8800 – SuiteCRM 7.11.11 Second-Order PHP Object Injection
https://notcve.org/view.php?id=CVE-2020-8800
SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection. SuiteCRM versiones hasta 7.11.11, permite una Inyección de objeto PHP de la función EmailsControllerActionGetFromFields. SuiteCRM versions 7.11.11 and below suffer from a second-order php object injection vulnerability. • http://packetstormsecurity.com/files/156321/SuiteCRM-7.11.11-Second-Order-PHP-Object-Injection.html https://seclists.org/fulldisclosure/2020/Feb/3 https://suitecrm.com • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •
CVE-2018-20816
https://notcve.org/view.php?id=CVE-2018-20816
An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a phished URL, with script executed. Una vulnerabilidad de Cross-Site Scripting (XSS) combinada con una de Cross-Site Request Forgery (CSRF) descubierta en SalesAgility SuiteCRM, en las versiones 7.x anteriores a la 7.8.24, y en las 7.10.x anteriores a la 7.10.11, conduce a un robo de cookies también conocido como un secuestro de sesión. Este problema afecta a la funcionalidad "add dashboard pages" donde los usuarios pueden recibir un ataque malicioso mediante una URL suplantada con script ejecutado. • https://docs.suitecrm.com/admin/releases/7.10.x/#_7_10_11 https://docs.suitecrm.com/admin/releases/7.8.x/#_7_8_24 https://github.com/salesagility/SuiteDocs/pull/198/files • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2018-15606
https://notcve.org/view.php?id=CVE-2018-15606
An XSS issue was discovered in SalesAgility SuiteCRM 7.x before 7.8.21 and 7.10.x before 7.10.8, related to phishing an error message. Se ha descubierto un problema de Cross-Site Scripting (XSS) en SalesAgility SuiteCRM en versiones 7.x anteriores a la 7.8.21 y versiones 7.10.x anteriores a la 7.10.8, relacionado con la suplantación de un mensaje de error. • https://docs.suitecrm.com/admin/releases/#anchor-7.10.8 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2015-5947
https://notcve.org/view.php?id=CVE-2015-5947
SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code. SuiteCRM, en versiones anteriores a la 7.2.3, permite que atacantes remotos ejecuten código arbitrario. • http://www.openwall.com/lists/oss-security/2015/08/06/6 https://github.com/XiphosResearch/exploits/tree/master/suiteshell https://github.com/salesagility/SuiteCRM/commit/b1b3fd61c7697ad2073cd253d31c9462929e7bb5 https://github.com/salesagility/SuiteCRM/issues/333 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2015-5948
https://notcve.org/view.php?id=CVE-2015-5948
Race condition in SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-5947. Una condición de carrera en versiones anteriores a la 7.2.3 de SuiteCRM permite que atacantes remotos ejecuten código arbitrario. NOTA: Esta vulnerabilidad existe debido a una solución incompleta para CVE-2015-5947. • http://www.openwall.com/lists/oss-security/2015/08/06/6 https://github.com/XiphosResearch/exploits/tree/master/suiteshell https://github.com/salesagility/SuiteCRM/commit/b1b3fd61c7697ad2073cd253d31c9462929e7bb5 https://github.com/salesagility/SuiteCRM/issues/333 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •