SuiteCRM
SQL injection through the legacy SOAP portal_get_entry_list methodDetails
Summary
A low-privileged portal API context could pass SQL expressions through the where and order_by inputs of portal_get_entry_list. Insufficient sanitization during query construction allowed blind extraction of database metadata and potentially sensitive data. Depending on the query context and database permissions, an attacker could also manipulate data or degrade performance with complex queries. On MySQL installations with FILE privilege, SELECT INTO OUTFILE could potentially lead to code execution.
Disclosure timeline
- Reported the vulnerability to SuiteCRM.
- Report acknowledged by SuiteCRM.
- Report accepted by SuiteCRM.
- Fixing SuiteCRM 7.15.2 and 8.10.2 releases published.
- CVE assigned.
- Security advisory publication pending.