First published: Tue Jan 07 2025(Updated: )
An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SuiteCRM | ||
SugarCRM | =7.12.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45186 has been classified as a medium severity vulnerability because it allows authenticated users to recover arbitrary database fields.
To fix CVE-2022-45186, upgrade SuiteCRM to version 7.12.8 or later, which addresses this vulnerability.
CVE-2022-45186 affects users of SuiteCRM version 7.12.7 and earlier who have authenticated access.
CVE-2022-45186 allows authenticated users to access and recover arbitrary fields from the database.
CVE-2022-45186 is a local vulnerability since it requires authenticated access to exploit.