Описание
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prior to 8.6.1 allows for Host Header Injection when directly accessing the /legacy route. Version 8.6.1 contains a patch for the issue.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 8.6.1 (исключая)
cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*
EPSS
Процентиль: 50%
0.00269
Низкий
4.3 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-601
CWE-601
EPSS
Процентиль: 50%
0.00269
Низкий
4.3 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-601
CWE-601