CVE-2024-36409
SuiteCRM authenticated SQL Injection in TreeData entrypoint
8.8
HIGH
CVSS 3.1
EPSS 0.29%
Description
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in Tree data entry point. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
How to fix CVE-2024-36409
To remediate CVE-2024-36409, upgrade the affected package to a fixed version below.
- —upgrade to 7.14.4 or later
Is CVE-2024-36409 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 7.14.4, >= 8.0.0, < 8.6.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |