GHSA-cx24-rr7r-mxrg GHSA-239h-ffjr-v957 GHSA-3phg-q9w9-4pqw GHSA-gjgm-wrr6-hrmp GHSA-pjc8-2w2x-xcgf GHSA-mjjw-75gv-j5g5 GHSA-5m7h-v4v6-2r8h GHSA-7cj5-pc2f-9xgv GHSA-pmhw-r27f-w92m GHSA-pqq6-v2mj-hrm2
SuiteCRM flaws before 7.15.2 and 8.10.2 allow SQL injection, code execution and account takeover
SuiteCRM before 7.15.2 and before 8.10.2 has SQL injection, local file inclusion to RCE, and a password-reset account takeover flaw. An authenticated user can read or modify the database or execute code. Upgrade to SuiteCRM 7.15.2 or 8.10.2; the password-reset flaw is fixed in SuiteCRM-Core 8.10.2.
What happened
SuiteCRM's maintainers have published a set of security advisories fixed in the 7.15.2 and 8.10.2 releases. The most severe is GHSA-cx24-rr7r-mxrg, a local file inclusion flaw in the AOW_WorkFlow module. Any authenticated user with the WorkFlow role can inject path traversal sequences into the aow_action GET parameter, causing require_once() to execute arbitrary PHP files. The advisory records that this achieves remote code execution and can be used to deploy a web-accessible webshell.
Several authenticated SQL injection flaws are also included. Through REST API calls, report conditions, campaign popups, project task queries and map markers, a low-privileged user can supply crafted input that reaches SQL statements without proper parameterisation. Depending on the flaw, an attacker can read the full database, extract administrator password hashes and OAuth tokens, modify records, or run database operations such as SELECT INTO OUTFILE where the database user has FILE privilege.
GHSA-mjjw-75gv-j5g5 is a password reset flaw fixed in SuiteCRM-Core 8.10.2. A logic weakness allows an attacker with a valid reset token for any account to change the password of another account, including an administrator. None of the advisories records active exploitation.
Who is affected
SuiteCRM versions before 7.15.2 and before 8.10.2 are affected by nine of the advisories, including the local file inclusion and SQL injection flaws. SuiteCRM-Core 8.8.0 to before 8.10.2 is affected by the password reset account takeover advisory GHSA-mjjw-75gv-j5g5. Check whether your deployment is on a 7.x or 8.x branch and identify which component you are running.
What to do now
- Identify every SuiteCRM and SuiteCRM-Core deployment and confirm the current branch and version.
- Apply the fixed releases listed for the affected components: upgrade SuiteCRM to 7.15.2 or 8.10.2 to address the local file inclusion and SQL injection advisories, and upgrade SuiteCRM-Core to 8.10.2 for GHSA-mjjw-75gv-j5g5.
- No workaround is published in these advisories. If you cannot upgrade immediately, restrict network access to the SuiteCRM instance to trusted users and monitor authentication and application logs for unusual authenticated activity until patching is complete.
- After patching, review user accounts and rotate credentials for accounts whose hashes or tokens may have been readable, as described in the SQL injection advisories.
How to detect it
The advisories describe time-based blind SQL injection techniques that use SLEEP payloads, so unusually slow responses from authenticated report, campaign, project or REST API requests may warrant investigation. The local file inclusion advisory notes that an attacker can deploy a web-accessible webshell; review the web root for unexpected PHP files and watch for anomalous use of AOW_WorkFlow.
Beyond the patch
These flaws turn a single set of user credentials into full database or server compromise. After patching, put in place the monitoring and patch-cycle tracking that catch this kind of abuse early. Managed Detection & Response (MDR) watches for the code execution, privilege escalation and credential abuse these advisories describe, while Supply Chain Defense & Third-Party Risk tracks how quickly upstream vendors fix flaws so your exposure window is visible.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| GHSA-cx24-rr7r-mxrg, GHSA-3phg-q9w9-4pqw, GHSA-gjgm-wrr6-hrmp, GHSA-pjc8-2w2x-xcgf, GHSA-5m7h-v4v6-2r8h, GHSA-7cj5-pc2f-9xgv, GHSA-pmhw-r27f-w92m, GHSA-pqq6-v2mj-hrm2 SuiteCRM | – < 7.15.2 – < 8.10.2 | 7.15.2 8.10.2 8.10.2 |
| GHSA-239h-ffjr-v957 SuiteCRM | – < 8.10.2 – < 7.15.2 | 8.10.2 7.15.2 8.10.2 |
| GHSA-mjjw-75gv-j5g5 SuiteCRM-Core | 8.8.0 – < 8.10.2 | 8.10.2 8.10.2 |
References
Vendor advisory
- LFI to RCE via AOW_WorkFlow
- Authenticated SQL Injection in AOR_Reports `parameter_value` (value_type=Field) allows …
- SQL Injection via REST API securexss() Bypass in Relationship Management
- Authenticated SQL Injection in v4_1 get_entry_list rest api
- Authenticated SQL Injection in map_markers distance Parameter
- Password Reset Account Takeover (Token-User Mismatch)
- SQL injection via id param in modules/Campaigns/PopupCampaignRoi.php
- Authenticated SQL Injection in get_end_date function in Project Controller