Improper access control in SuiteCRM - CVE-2024-36407
Published: June 10, 2024 / Updated: April 24, 2026
SuiteCRM
SalesAgility
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper access control in the password reset functionality when handling password reset requests. A remote attacker can trigger a password reset for a user account to cause a denial of service.
Only instances with password reset functionality enabled and running on php 7 are vulnerable.