CVE-2024-45392
CVSS V2 None
CVSS V3 None
Description
SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Versions 7.14.5 and 8.6.2 contain a patch for the issue.
Overview
- CVE ID
- CVE-2024-45392
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-09-05T16:34:14.271Z
- Last Modified Date
- 2024-09-05T17:43:20.061Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/salesagility/SuiteCRM/security/advisories/GHSA-8qfx-h7pm-2587 | x_refsource_CONFIRM |
https://docs.suitecrm.com/admin/releases/7.14.x/#_7_14_5 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-45392 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45392 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-09-06 13:05:56 | Added to TrackCVE |