ZeroHour

CVE-2023-6388

PoC
CVSS 3.1
5.0 medium
EPSS
<1%p39
Published
()
Modified
Description

Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the application is vulnerable to SSRF.

Vendors
salesagility
Products
suitecrm
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.