8.8
CVSSv3

CVE-2021-45897

Published: 28/01/2022 Updated: 10/02/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SuiteCRM prior to 7.12.3 and 8.x prior to 8.0.2 allows remote code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

salesagility suitecrm

salesagility suitecrm 8.0

Github Repositories

PoC for CVE-2021-45897

CVE-2021-45897 PoC for CVE-2021-45897 aka SCRMBT-#180 - RCE via Email-Templates (Authenticated only) in SuiteCRM <= 801 This vulnerability was reported to SalesAgility in fixed in SuiteCRM 7123 and SuiteCRM Core 802 If you are using older versions of SuiteCRM, I highly advise you to update Usage Installation Make sure to have a recent version of python3 and pip