#VU127390 Input validation error in SuiteCRM - CVE-2024-50333
Published: November 5, 2024 / Updated: April 24, 2026
SuiteCRM
SalesAgility
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper input validation in ParserLabel::addLabels() when writing user-supplied input to the filesystem. A remote privileged user can write attacker-controlled data into a custom language file to execute arbitrary code.
The crafted language file is included at runtime.