SalesAgility SuiteCRM
cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*
- < 7.12.6
A SQL injection vulnerability has been identified in SalesAgility SuiteCRM versions prior to 7.12.6. The issue arises in the 'export' functionality, specifically within the 'uid' parameter processing. This vulnerability allows remote, unauthenticated attackers to execute arbitrary code on the server.
Exploitation of this vulnerability allows for SQL injection, which could be used to manipulate database queries. In this case, it could lead to remote code execution on the server.
Users are advised to upgrade to SuiteCRM version 7.12.6 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.