SuiteCRM Uncontrolled User Input Leading to PHP Object Injection Vulnerability Allowing Remote Code Execution
Vulnerability
A vulnerability exists in SuiteCRM versions 7.14.6 and 8.8.0, where user input is not properly validated or sanitized before being passed to the unserialize function. This oversight could result in PHP object injection, allowing for remote code execution. Such remote code execution vulnerabilities can lead to severe consequences, including unauthorized access to sensitive data, privilege escalation, and exploitation of the application or server to deploy ransomware or cryptomining malware. The vulnerability has been addressed in SuiteCRM versions 7.14.7 and 8.8.1.
Impact
Exploitation of this vulnerability allows for remote code execution on the server where SuiteCRM is hosted.
Remediation
Users can upgrade to SuiteCRM versions 7.14.7 or 8.8.1 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
