VendorsSalesAgilitysuitecrm8.0
Vulnerabilities

SalesAgility SuiteCRM 8.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-45899
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
Published 2022-01-28 · Modified
9.8EPSS 0.022
CVE-2021-45898
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.
Published 2022-01-28 · Modified
9.8EPSS 0.011
CVE-2021-45897
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.
Published 2022-01-28 · Modified
8.8EPSS 0.046
CVE-2021-45041
SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.
Published 2021-12-19 · Modified
8.8EPSS 0.022