SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.
{ "cpes": [ "cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*" ], "severity": "High" }