SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution
Published Mar 7, 2022
8.8
HIGHCVSS 3.1
EPSS 53.23%
Description
SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a malicious report, containing a PHP-deserialization payload in the email_recipients field. Once someone accesses this report, the backend will deserialize the content of the email_recipients field and the payload gets executed. Project dependencies include a number of interesting PHP deserialization gadgets (e.g., Monolog/RCE1 from phpggc) that can be used for Code Execution.
Affected products
No data.
- < 7.12.5
- ≥ 8.0 · < 8.0.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://docs.suitecrm.com/8.x/admin/releases/8.0/ x_refsource_MISCRelease NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-28859 Advisory
- https://github.com/manuelz120 x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://docs.suitecrm.com/8.x/admin/releases/8.0/ | x_refsource_MISCRelease NotesVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-28859 | Advisory | |
| https://github.com/manuelz120 | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data