#VU127391 SQL injection in SuiteCRM - CVE-2024-49773
Published: November 5, 2024 / Updated: April 24, 2026
SuiteCRM
SalesAgility
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to SQL injection in the export entry point when processing the current_post parameter through generateSearchWhere(). A remote user can send a specially crafted current_post parameter to disclose sensitive information.
The issue can be exploited as a blind SQL injection and may expose PII.