An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.
History

Wed, 08 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jan 2025 19:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-01-07T00:00:00

Updated: 2025-01-08T18:00:17.215Z

Reserved: 2022-11-11T00:00:00

Link: CVE-2022-45185

cve-icon Vulnrichment

Updated: 2025-01-08T17:59:44.496Z

cve-icon NVD

Status : Received

Published: 2025-01-07T20:15:28.173

Modified: 2025-01-08T18:15:13.847

Link: CVE-2022-45185

cve-icon Redhat

No data.