manuelz120

3 exploits Active since Dec 2021
CVE-2022-23940 NOMISEC HIGH WORKING POC
SuiteCRM <8.0.1 - Authenticated RCE
SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a malicious report, containing a PHP-deserialization payload in the email_recipients field. Once someone accesses this report, the backend will deserialize the content of the email_recipients field and the payload gets executed. Project dependencies include a number of interesting PHP deserialization gadgets (e.g., Monolog/RCE1 from phpggc) that can be used for Code Execution.
12 stars
CVSS 8.8
CVE-2021-45041 NOMISEC HIGH WORKING POC
Salesagility Suitecrm < 7.12.2 - SQL Injection
SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.
CVSS 8.8
CVE-2021-45897 WRITEUP HIGH WORKING POC
SuiteCRM <7.12.3, <8.0.2 - RCE
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.
CVSS 8.8