An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.
Link | Tags |
---|---|
https://docs.suitecrm.com/admin/releases/7.12.x/ | release notes |
https://github.com/Orange-Cyberdefense/CVE-repository/ | third party advisory exploit |
https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/poc_SuiteCRM.py | exploit |