docs.suitecrm.com
https://docs.suitecrm.com/admin/releases/7.14.x CVE-2024-36416
HIGH
SuiteCRM v4 API Excessive log data DOS
Record summary
CVE-2024-36416 has a selected CVSS score of 8.6 (high); EIP currently links 1 repository PoC.
Description
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a deprecated v4 API example with no log rotation allows denial of service by logging excessive data. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 11, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SuiteCRMBrowse salesagility / SuiteCRMDefault status: affected | CVE List | < 7.14.4 | affected |
| >= 8.0.0, < 8.6.1 | affected | ||
| 7.0.0 to < 7.14.4 | affected | ||
| 8.0.0 to < 8.6.1 | affected |
Proofs of concept
1Repository PoCs
GitHubkva55/CVE-2024-36416Repository PoCby kva55Stars: 0Not analyzed3 files
References
3github.com
https://github.com/kva55/CVE-2024-36416 github.comConfirmation
https://github.com/salesagility/SuiteCRM/security/advisories/GHSA-jrpp-22g3-2j77