CVE-2023-6388 – Suite CRM v7.14.2 - SSRF
https://notcve.org/view.php?id=CVE-2023-6388
Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the application is vulnerable to SSRF. La versión 7.14.2 de Suite CRM permite realizar solicitudes HTTP arbitrarias a través del servidor vulnerable. Esto es posible porque la aplicación es vulnerable a SSRF. • https://fluidattacks.com/advisories/leon https://github.com/salesagility/SuiteCRM • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2023-6131 – Code Injection in salesagility/suitecrm
https://notcve.org/view.php?id=CVE-2023-6131
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. Inyección de código en el repositorio de GitHub salesagility/suitecrm anterior a 7.14.2, 7.12.14, 8.4.2. • https://github.com/salesagility/suitecrm/commit/54bc56c3bd9f1db75408db1c1d7d652c3f5f71e9 https://huntr.com/bounties/5fa50b25-f6b1-408c-99df-4442c86c563f • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2023-6130 – Path Traversal: '\..\filename' in salesagility/suitecrm
https://notcve.org/view.php?id=CVE-2023-6130
Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. Path Traversal: '\..\filename' en el repositorio de GitHub salesagility/suitecrm anterior a 7.14.2, 7.12.14, 8.4.2. • https://github.com/salesagility/suitecrm/commit/54bc56c3bd9f1db75408db1c1d7d652c3f5f71e9 https://huntr.com/bounties/22a27be9-f016-4daf-9887-c77eb3e1dc74 • CWE-29: Path Traversal: '\..\filename' •
CVE-2023-6128 – Cross-site Scripting (XSS) - Reflected in salesagility/suitecrm
https://notcve.org/view.php?id=CVE-2023-6128
Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. Cross-site Scripting (XSS) Reflejados en el repositorio de GitHub salesagility/suitecrm anteriores a 7.14.2, 7.12.14, 8.4.2. • https://github.com/salesagility/suitecrm/commit/54bc56c3bd9f1db75408db1c1d7d652c3f5f71e9 https://huntr.com/bounties/51406547-1961-45f2-a416-7f14fd775d2d • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-6127 – Unrestricted Upload of File with Dangerous Type in salesagility/suitecrm
https://notcve.org/view.php?id=CVE-2023-6127
Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. Carga sin restricciones de archivos con tipo peligroso en el repositorio de GitHub salesagility/suitecrm anterior a 7.14.2, 7.12.14, 8.4.2. • https://github.com/salesagility/suitecrm/commit/54bc56c3bd9f1db75408db1c1d7d652c3f5f71e9 https://huntr.com/bounties/bf10c72b-5d2e-4c9a-9bd6-d77bdf31027d • CWE-434: Unrestricted Upload of File with Dangerous Type •