ZeroHour

CVE-2022-45185

PoC ×2
CVSS 3.1
8.8 high
EPSS
1%p65
Published
()
Modified
Description

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.

Vendors
salesagility
Products
suitecrm
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.