Filtered by vendor Salesagility Subscriptions
Total 83 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2018-20816 1 Salesagility 1 Suitecrm 2024-08-05 N/A
An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a phished URL, with script executed.
CVE-2018-15606 1 Salesagility 1 Suitecrm 2024-08-05 N/A
An XSS issue was discovered in SalesAgility SuiteCRM 7.x before 7.8.21 and 7.10.x before 7.10.8, related to phishing an error message.
CVE-2019-18784 1 Salesagility 1 Suitecrm 2024-08-05 9.8 Critical
SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection.
CVE-2019-18782 1 Salesagility 1 Suitecrm 2024-08-05 5.3 Medium
SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism.
CVE-2019-16922 1 Salesagility 1 Suitecrm 2024-08-05 5.3 Medium
SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allows unintended public exposure of files.
CVE-2019-14752 1 Salesagility 1 Suitecrm 2024-08-05 6.1 Medium
SuiteCRM 7.10.x and 7.11.x before 7.10.20 and 7.11.8 has XSS.
CVE-2019-14454 1 Salesagility 1 Suitecrm 2024-08-05 9.8 Critical
SuiteCRM 7.11.x and 7.10.x before 7.11.8 and 7.10.20 is vulnerable to vertical privilege escalation.
CVE-2019-13335 1 Salesagility 1 Suitecrm 2024-08-04 9.8 Critical
SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.
CVE-2019-12598 1 Salesagility 1 Suitecrm 2024-08-04 N/A
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3).
CVE-2019-12600 1 Salesagility 1 Suitecrm 2024-08-04 N/A
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3).
CVE-2019-12601 1 Salesagility 1 Suitecrm 2024-08-04 N/A
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 3 of 3).
CVE-2019-12599 1 Salesagility 1 Suitecrm 2024-08-04 N/A
SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection.
CVE-2019-6506 1 Salesagility 1 Suitecrm 2024-08-04 N/A
SuiteCRM before 7.8.28, 7.9.x and 7.10.x before 7.10.15, and 7.11.x before 7.11.3 allows SQL Injection.
CVE-2020-28328 1 Salesagility 1 Suitecrm 2024-08-04 8.8 High
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.
CVE-2020-15301 1 Salesagility 1 Suitecrm 2024-08-04 7.8 High
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.
CVE-2020-15300 1 Salesagility 1 Suitecrm 2024-08-04 6.1 Medium
SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document.
CVE-2020-14208 1 Salesagility 1 Suitecrm 2024-08-04 5.4 Medium
SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.
CVE-2020-8785 1 Salesagility 1 Suitecrm 2024-08-04 9.8 Critical
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4).
CVE-2020-8786 1 Salesagility 1 Suitecrm 2024-08-04 9.8 Critical
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4).
CVE-2020-8804 1 Salesagility 1 Suitecrm 2024-08-04 6.5 Medium
SuiteCRM through 7.11.10 allows SQL Injection via the SOAP API, the EmailUIAjax interface, or the MailMerge module.