CVE-2024-36410
SuiteCRM authenticated SQL Injection in EmailUIAjax messages count controller
8.8
HIGH
CVSS 3.1
EPSS 0.09%
Description
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in EmailUIAjax messages count controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
How to fix CVE-2024-36410
To remediate CVE-2024-36410, upgrade the affected package to a fixed version below.
- —upgrade to 7.14.4 or later
Is CVE-2024-36410 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 7.14.4, >= 8.0.0, < 8.6.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |