Jack Anderson
19 exploits
Active since Feb 2023
SuiteCRM < 7.14.1 - SQL Injection
CVSS 9.1
SuiteCRM < 7.12.9 - Path Traversal via Backslash Sequence
CVSS 8.8
SuiteCRM 8.0.0-8.0.3 - Stored Cross-Site Scripting
CVSS 4.8
GitHub salesagility/suitecrm-core <8.3.1 - CSRF
CVSS 8.8
SuiteCRM < 8.4.2 - Unauthenticated Exposure of Sensitive Information via GraphQL Introspection
CVSS 3.1
SuiteCRM < 7.14.1 - Stored Cross-Site Scripting
CVSS 5.4
SuiteCRM < 7.14.1 - Improper Access Control
CVSS 6.5
salesagility/suitecrm <7.14.2-8.4.2-7.12.14 - SSRF
CVSS 4.3
GitHub salesagility/suitecrm <7.14.2-8.4.2 - Code Injection
CVSS 8.8
salesagility/suitecrm <7.14.2-8.4.2 - Code Injection
CVSS 9.8
SuiteCRM < 7.12.14 - Unrestricted Upload of File with Dangerous Type
CVSS 5.4
GitHub salesagility/suitecrm <7.14.2-8.4.2 - XSS
CVSS 5.4
salesagility/suitecrm <7.14.2-8.4.2 - Path Traversal
CVSS 8.8
salesagility/suitecrm <7.14.2-8.4.2 - Code Injection
CVSS 8.8
SuiteCRM < 7.14.8 and 8.0.0-beta.1-8.9.0 - SQL Injection via Crafted call_id
CVSS 8.8
SuiteCRM < 7.14.8 and 8.0.0-beta.1-8.9.0 - SQL Injection via Crafted call_id
CVSS 8.8
SuiteCRM < 7.14.8 - Privilege Escalation via Inactive User Session Persistence
CVSS 8.3
SuiteCRM < 7.14.8 - Privilege Escalation via Inactive User Session Persistence
CVSS 8.3
SuiteCRM < 7.14.8 - Unauthenticated Reflected Cross-Site Scripting
CVSS 6.1