CVE-2022-45185

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:salesagility:suitecrm:7.12.7:*:*:*:*:*:*:*

History

15 Apr 2025, 18:38

Type Values Removed Values Added
CPE cpe:2.3:a:salesagility:suitecrm:7.12.7:*:*:*:*:*:*:*
First Time Salesagility
Salesagility suitecrm
References () https://github.com/Orange-Cyberdefense/CVE-repository/ - () https://github.com/Orange-Cyberdefense/CVE-repository/ - Exploit, Third Party Advisory
References () https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/poc_SuiteCRM.py - () https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/poc_SuiteCRM.py - Exploit
References () https://docs.suitecrm.com/admin/releases/7.12.x/ - () https://docs.suitecrm.com/admin/releases/7.12.x/ - Release Notes

07 Jan 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-07 20:15

Updated : 2025-04-15 18:38


NVD link : CVE-2022-45185

Mitre link : CVE-2022-45185


JSON object : View

Products Affected

salesagility

  • suitecrm
CWE

No CWE.