BIT-suitecrm-2025-54786

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/suitecrm/BIT-suitecrm-2025-54786.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-suitecrm-2025-54786
Aliases
Published
2025-08-18T08:14:17Z
Modified
2025-08-18T08:59:33Z
Summary
SuiteCRM: Legacy iCal service allows unauthenticated access to meeting data
Details

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken authentication in the legacy iCal service allows unauthenticated access to meeting data. An unauthenticated actor can view any user's meeting (calendar event) data given their username, related functionality allows user enumeration. This is fixed in versions 7.14.7 and 8.8.1.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*"
    ],
    "severity":  "Medium"
}
References

Affected packages

Bitnami / suitecrm

Package

Name
suitecrm
Purl
pkg:bitnami/suitecrm

Severity

  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
7.14.6
Fixed
7.14.7
Introduced
8.8.0
Fixed
8.8.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/suitecrm/BIT-suitecrm-2025-54786.json"