Lucene search

K
ripstechRIPS Technologies BlogRIPSTECH:66E3BCF7301B13699D70FD24FA47C590
HistoryAug 20, 2019 - 11:00 a.m.

Breaking Into Your Company's Internal Network - SuiteCRM 7.11.4

2019-08-2011:00:00
RIPS Technologies Blog
blog.ripstech.com
24

EPSS

0.001

Percentile

49.5%

As part of our efforts to make the open source web application space more secure we scanned SuiteCRM 7.11.4 with our static code analysis tool RIPS and we detected multiple critical vulnerabilities. Among them is a SQL Injection that can be exploited as a normal user (CVE-2019-12598), which can be leveraged into a multi-step PHP Object Injection leading to a Remote Code Execution (CVE-2019-12601) giving an attacker full control of the underlying server.

EPSS

0.001

Percentile

49.5%

Related for RIPSTECH:66E3BCF7301B13699D70FD24FA47C590