SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resourceid and startdate.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-45041.json"