BIT-suitecrm-2024-36407

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/suitecrm/BIT-suitecrm-2024-36407.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-suitecrm-2024-36407
Aliases
Published
2024-06-12T07:39:14.510Z
Modified
2024-06-13T07:56:36.653Z
Summary
[none]
Details

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, a user password can be reset from an unauthenticated attacker. The attacker does not get access to the new password. But this can be annoying for the user. This attack is also dependent on some password reset functionalities being enabled. It also requires the system using php 7, which is not an officially supported version. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

References

Affected packages

Bitnami / suitecrm

Package

Name
suitecrm
Purl
pkg:bitnami/suitecrm

Severity

  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.14.4
Introduced
8.0.0
Fixed
8.6.1