CVE-2022-45185

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:salesagility:suitecrm:7.12.7:*:*:*:*:*:*:*

History

15 Apr 2025, 18:38

Type Values Removed Values Added
First Time Salesagility
Salesagility suitecrm
CPE cpe:2.3:a:salesagility:suitecrm:7.12.7:*:*:*:*:*:*:*
References () https://docs.suitecrm.com/admin/releases/7.12.x/ - () https://docs.suitecrm.com/admin/releases/7.12.x/ - Release Notes
References () https://github.com/Orange-Cyberdefense/CVE-repository/ - () https://github.com/Orange-Cyberdefense/CVE-repository/ - Exploit, Third Party Advisory
References () https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/poc_SuiteCRM.py - () https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/poc_SuiteCRM.py - Exploit

08 Jan 2025, 18:15

Type Values Removed Values Added
CWE CWE-502
Summary
  • (es) Se descubrió un problema en SuiteCRM 7.12.7. Los usuarios autenticados pueden usar funciones de CRM para cargar archivos maliciosos. Luego, se puede usar la deserialización para lograr la ejecución del código.
References () https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/poc_SuiteCRM.py - () https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/poc_SuiteCRM.py -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

07 Jan 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-07 20:15

Updated : 2025-04-15 18:38


NVD link : CVE-2022-45185

Mitre link : CVE-2022-45185

CVE.ORG link : CVE-2022-45185


JSON object : View

Products Affected

salesagility

  • suitecrm
CWE
CWE-502

Deserialization of Untrusted Data