An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.
History

Tue, 15 Apr 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Salesagility
Salesagility suitecrm
CPEs cpe:2.3:a:salesagility:suitecrm:7.12.7:*:*:*:*:*:*:*
Vendors & Products Salesagility
Salesagility suitecrm

Wed, 08 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jan 2025 19:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-01-08T18:00:17.215Z

Reserved: 2022-11-11T00:00:00

Link: CVE-2022-45185

cve-icon Vulnrichment

Updated: 2025-01-08T17:59:44.496Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-07T20:15:28.173

Modified: 2025-04-15T18:38:13.663

Link: CVE-2022-45185

cve-icon Redhat

No data.