CVE-2022-45186

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.
Configurations

Configuration 1 (hide)

cpe:2.3:a:salesagility:suitecrm:7.12.7:*:*:*:*:*:*:*

History

15 Apr 2025, 18:33

Type Values Removed Values Added
CPE cpe:2.3:a:salesagility:suitecrm:7.12.7:*:*:*:*:*:*:*
First Time Salesagility suitecrm
Salesagility
CWE NVD-CWE-noinfo
References () https://docs.suitecrm.com/admin/releases/7.12.x/ - () https://docs.suitecrm.com/admin/releases/7.12.x/ - Release Notes
References () https://github.com/Orange-Cyberdefense/CVE-repository/ - () https://github.com/Orange-Cyberdefense/CVE-repository/ - Exploit, Third Party Advisory
References () https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/poc_SuiteCRM.py - () https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/poc_SuiteCRM.py - Exploit

08 Jan 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
Summary
  • (es) Se descubrió un problema en SuiteCRM 7.12.7. Los usuarios autenticados pueden recuperar un campo arbitrario de una base de datos.

07 Jan 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-07 20:15

Updated : 2025-04-15 18:33


NVD link : CVE-2022-45186

Mitre link : CVE-2022-45186

CVE.ORG link : CVE-2022-45186


JSON object : View

Products Affected

salesagility

  • suitecrm