CVE-2022-45185

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:salesagility:suitecrm:7.12.7:*:*:*:*:*:*:*

History

15 Apr 2025, 18:38

Type Values Removed Values Added
References () https://docs.suitecrm.com/admin/releases/7.12.x/ - () https://docs.suitecrm.com/admin/releases/7.12.x/ - Release Notes
References () https://github.com/Orange-Cyberdefense/CVE-repository/ - () https://github.com/Orange-Cyberdefense/CVE-repository/ - Exploit, Third Party Advisory
References () https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/poc_SuiteCRM.py - () https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/poc_SuiteCRM.py - Exploit
First Time Salesagility suitecrm
Salesagility
CPE cpe:2.3:a:salesagility:suitecrm:7.12.7:*:*:*:*:*:*:*

08 Jan 2025, 18:15

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en SuiteCRM 7.12.7. Los usuarios autenticados pueden usar funciones de CRM para cargar archivos maliciosos. Luego, se puede usar la deserialización para lograr la ejecución del código.
References () https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/poc_SuiteCRM.py - () https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/poc_SuiteCRM.py -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-502

07 Jan 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-07 20:15

Updated : 2025-04-15 18:38


NVD link : CVE-2022-45185

Mitre link : CVE-2022-45185

CVE.ORG link : CVE-2022-45185


JSON object : View

Products Affected

salesagility

  • suitecrm
CWE
CWE-502

Deserialization of Untrusted Data