SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prior to 8.6.1 allows for Host Header Injection when directly accessing the `/legacy` route. Version 8.6.1 contains a patch for the issue.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/salesagility/SuiteCRM-Core/security/advisories/GHSA-3323-hjq3-c6vc | Third Party Advisory | 
| https://github.com/salesagility/SuiteCRM-Core/security/advisories/GHSA-3323-hjq3-c6vc | Third Party Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2024-06-10 22:15
Updated : 2024-11-21 09:22
NVD link : CVE-2024-36419
Mitre link : CVE-2024-36419
CVE.ORG link : CVE-2024-36419
JSON object : View
Products Affected
                salesagility
- suitecrm
CWE
                
                    
                        
                        CWE-601
                        
            URL Redirection to Untrusted Site ('Open Redirect')
