SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resourceid and startdate.
{ "cpes": [ "cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*", "cpe:2.3:a:salesagility:suitecrm:8.0.0:*:*:*:*:*:*:*" ], "severity": "High" }