CVE-2024-45392
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/09/2024
Last modified:
06/09/2024
Description
SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Versions 7.14.5 and 8.6.2 contain a patch for the issue.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:* | 7.14.5 (excluding) | |
| cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:* | 8.0.0 (including) | 8.6.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



