CVE-2022-50589

SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within theprocessing of the uid parameter within the export functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
VulnCheckCNA
---
---
CISA-ADPADP
---
---