CVE-2024-36412

CRITICAL NUCLEI

SuiteCRM <7.14.4-8.6.1 - SQL Injection

Title source: llm

Description

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for a SQL injection attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

Exploits (1)

github WORKING POC 4 stars
by halilkirazkaya · poc
https://github.com/halilkirazkaya/cve-poc-garage/tree/main/2024/CVE-2024-36412.md

Nuclei Templates (1)

SuiteCRM - SQL Injection
CRITICALVERIFIEDby s4e-io
Shodan: title:"SuiteCRM"
FOFA: title="SuiteCRM"

Scores

CVSS v3 10.0
EPSS 0.9364
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
salesagility/suitecrm < 7.14.4
Published Jun 10, 2024
Tracked Since Feb 18, 2026