CVE-2019-18785

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
20/03/2020
Last modified:
24/03/2020

Description

SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:suitecrm:suitecrm:*:*:*:*:*:*:*:* 7.10.0 (including) 7.10.21 (excluding)
cpe:2.3:a:suitecrm:suitecrm:*:*:*:*:*:*:*:* 7.11.0 (including) 7.11.9 (excluding)