← volver
CVE-2023-47643lowexplotación observadaCWE-200

SuiteCRM has Unauthenticated Graphql Introspection Enabled

45Vexday Risk Score

Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.

ssvc Actcvss 3.1epss 3.0%
de la publicación al arma
Publicada en NVD21 nov
VulnCheck+399d
probabilidad de explotación
3.0%top 14% de las CVE
explotación observada
VulnCheck
SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection is enabled without authentication, exposing the scheme defining all object types, arguments, and functions. An attacker can obtain the GraphQL schema and understand the entire attack surface of the API, including sensitive fields such as UserHash. This issue is patched in version 8.4.2. There are no known workarounds.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N