Skip to content

GHSA-cx24-rr7r-mxrg GHSA-239h-ffjr-v957 GHSA-3phg-q9w9-4pqw GHSA-gjgm-wrr6-hrmp GHSA-pjc8-2w2x-xcgf GHSA-mjjw-75gv-j5g5 GHSA-5m7h-v4v6-2r8h GHSA-7cj5-pc2f-9xgv GHSA-pmhw-r27f-w92m GHSA-pqq6-v2mj-hrm2

SuiteCRM flaws before 7.15.2 and 8.10.2 allow SQL injection, code execution and account takeover

Critical 9.9 Vendor: SuiteCRM Published

SuiteCRM before 7.15.2 and before 8.10.2 has SQL injection, local file inclusion to RCE, and a password-reset account takeover flaw. An authenticated user can read or modify the database or execute code. Upgrade to SuiteCRM 7.15.2 or 8.10.2; the password-reset flaw is fixed in SuiteCRM-Core 8.10.2.

What happened

SuiteCRM's maintainers have published a set of security advisories fixed in the 7.15.2 and 8.10.2 releases. The most severe is GHSA-cx24-rr7r-mxrg, a local file inclusion flaw in the AOW_WorkFlow module. Any authenticated user with the WorkFlow role can inject path traversal sequences into the aow_action GET parameter, causing require_once() to execute arbitrary PHP files. The advisory records that this achieves remote code execution and can be used to deploy a web-accessible webshell.

Several authenticated SQL injection flaws are also included. Through REST API calls, report conditions, campaign popups, project task queries and map markers, a low-privileged user can supply crafted input that reaches SQL statements without proper parameterisation. Depending on the flaw, an attacker can read the full database, extract administrator password hashes and OAuth tokens, modify records, or run database operations such as SELECT INTO OUTFILE where the database user has FILE privilege.

GHSA-mjjw-75gv-j5g5 is a password reset flaw fixed in SuiteCRM-Core 8.10.2. A logic weakness allows an attacker with a valid reset token for any account to change the password of another account, including an administrator. None of the advisories records active exploitation.

Who is affected

SuiteCRM versions before 7.15.2 and before 8.10.2 are affected by nine of the advisories, including the local file inclusion and SQL injection flaws. SuiteCRM-Core 8.8.0 to before 8.10.2 is affected by the password reset account takeover advisory GHSA-mjjw-75gv-j5g5. Check whether your deployment is on a 7.x or 8.x branch and identify which component you are running.

What to do now

  1. Identify every SuiteCRM and SuiteCRM-Core deployment and confirm the current branch and version.
  2. Apply the fixed releases listed for the affected components: upgrade SuiteCRM to 7.15.2 or 8.10.2 to address the local file inclusion and SQL injection advisories, and upgrade SuiteCRM-Core to 8.10.2 for GHSA-mjjw-75gv-j5g5.
  3. No workaround is published in these advisories. If you cannot upgrade immediately, restrict network access to the SuiteCRM instance to trusted users and monitor authentication and application logs for unusual authenticated activity until patching is complete.
  4. After patching, review user accounts and rotate credentials for accounts whose hashes or tokens may have been readable, as described in the SQL injection advisories.

How to detect it

The advisories describe time-based blind SQL injection techniques that use SLEEP payloads, so unusually slow responses from authenticated report, campaign, project or REST API requests may warrant investigation. The local file inclusion advisory notes that an attacker can deploy a web-accessible webshell; review the web root for unexpected PHP files and watch for anomalous use of AOW_WorkFlow.

Beyond the patch

These flaws turn a single set of user credentials into full database or server compromise. After patching, put in place the monitoring and patch-cycle tracking that catch this kind of abuse early. Managed Detection & Response (MDR) watches for the code execution, privilege escalation and credential abuse these advisories describe, while Supply Chain Defense & Third-Party Risk tracks how quickly upstream vendors fix flaws so your exposure window is visible.

Affected and fixed versions

ProductAffectedFixed in
GHSA-cx24-rr7r-mxrg, GHSA-3phg-q9w9-4pqw, GHSA-gjgm-wrr6-hrmp, GHSA-pjc8-2w2x-xcgf, GHSA-5m7h-v4v6-2r8h, GHSA-7cj5-pc2f-9xgv, GHSA-pmhw-r27f-w92m, GHSA-pqq6-v2mj-hrm2
SuiteCRM
– < 7.15.2
– < 8.10.2
7.15.2
8.10.2
8.10.2
GHSA-239h-ffjr-v957
SuiteCRM
– < 8.10.2
– < 7.15.2
8.10.2
7.15.2
8.10.2
GHSA-mjjw-75gv-j5g5
SuiteCRM-Core
8.8.0 – < 8.10.28.10.2
8.10.2

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them. Entries marked GHSA have no CVE: their source is the security advisory the maintainers published in their official GitHub repository.

Written with AI assistance from the sources above and checked automatically against them before publication.