← back
CVE-2022-45185

CVE-2022-45185

CVSS 8.8 HIGHEPSS 1.1%CWE-502
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 1.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
07 Jan 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →