#VU127389 Input validation error in SuiteCRM - CVE-2024-49774
Published: November 5, 2024 / Updated: April 24, 2026
SuiteCRM
SalesAgility
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper input validation in the ModuleScanner PHP script parsing logic when processing malicious module loader packages. A remote privileged user can use syntax constructions that bypass blacklist checks to execute arbitrary code.