because the application is vulnerable to LFI.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17382 | Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI. |
Tue, 31 Dec 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Salesagility
Salesagility suitecrm |
|
| CPEs | cpe:2.3:a:salesagility:suitecrm:7.14.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Salesagility
Salesagility suitecrm |
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2024-08-01T18:48:22.061Z
Reserved: 2024-02-19T20:59:31.188Z
Link: CVE-2024-1644
Updated: 2024-08-01T18:48:22.061Z
Status : Analyzed
Published: 2024-02-20T00:15:14.653
Modified: 2026-06-17T07:04:41.617
Link: CVE-2024-1644
No data.
OpenCVE Enrichment
No data.
-
CWE-434
Unrestricted Upload of File with Dangerous Type
EUVD