CVE-2022-45186
HIGHDescription
An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.
Is your site exposed to CVE-2022-45186?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| salesagility | suitecrm |
References
Frequently Asked Questions
What is CVE-2022-45186? +
How severe is CVE-2022-45186? +
What products are affected by CVE-2022-45186? +
How do I check if I'm vulnerable to CVE-2022-45186? +
Related Vulnerabilities
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events …
Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI.
SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ …
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation …
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation …
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation …