An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.
This Cyber News was published on www.tenable.com. Publication date: Wed, 08 Jan 2025 08:56:02 +0000