#VU127392 SQL injection in SuiteCRM - CVE-2024-49772
Published: November 5, 2024 / Updated: April 24, 2026
SuiteCRM
SalesAgility
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to SQL injection in the AM_ProjectTemplates controller when handling user-supplied input. A remote user can send a specially crafted request to disclose sensitive information.
The issue can be exploited by a low-privileged authenticated user.