CVE-2022-0755 – Missing Authorization in salesagility/suitecrm
https://notcve.org/view.php?id=CVE-2022-0755
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5. Un Control de Acceso Inapropiado en el repositorio de GitHub salesagility/suitecrm versiones anteriores a 7.12.5 • https://github.com/salesagility/suitecrm/commit/e93b269f637de313f45b32c58cef5ec012a34f58 https://huntr.dev/bounties/cc767dbc-c676-44c1-a9d1-cd17ae77ee7e • CWE-862: Missing Authorization •
CVE-2021-45899
https://notcve.org/view.php?id=CVE-2021-45899
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution. SuiteCRM versiones anteriores a 7.12.3 y 8.x versiones anteriores a 8.0.2, permite una deserialización de PHAR que puede conllevar a una ejecución de código remota • https://docs.suitecrm.com/8.x/admin/releases/8.0 https://docs.suitecrm.com/admin/releases/7.12.x • CWE-502: Deserialization of Untrusted Data •
CVE-2021-45898
https://notcve.org/view.php?id=CVE-2021-45898
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion. SuiteCRM versiones anteriores a 7.12.3 y 8.x versiones anteriores a 8.0.2, permite una inclusión de archivos locales • https://docs.suitecrm.com/8.x/admin/releases/8.0 https://docs.suitecrm.com/admin/releases/7.12.x •
CVE-2021-45897
https://notcve.org/view.php?id=CVE-2021-45897
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution. SuiteCRM versiones anteriores a 7.12.3 y 8.x versiones anteriores a 8.0.2, permite una ejecución de código remota • https://github.com/manuelz120/CVE-2021-45897 https://docs.suitecrm.com/8.x/admin/releases/8.0 https://docs.suitecrm.com/admin/releases/7.12.x •
CVE-2021-45903
https://notcve.org/view.php?id=CVE-2021-45903
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268. Un problema persistente de tipo cross-site scripting (XSS en la interfaz web de SuiteCRM versiones anteriores a 7.10.35, y en versiones 7.11.x y 7.12.x anteriores a 7.12.2, permite a un atacante remoto introducir JavaScript arbitrario por medio de la carga de archivos adjuntos, una vulnerabilidad diferente a la de CVE-2021-39267 y CVE-2021-39268 • https://docs.suitecrm.com/admin/releases/7.10.x/#_7_10_35 https://docs.suitecrm.com/admin/releases/7.12.x/#_7_12_2 https://github.com/ach-ing/cves/blob/main/CVE-2021-45903.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •