Vulnerability CVE-2024-1644


Published: 2024-02-20

Description:
Suite CRM version 7.14.2 allows including local php files. This is possible

because the application is vulnerable to LFI.



Type:

CWE-434

(Unrestricted Upload of File with Dangerous Type)

 References:
https://github.com/salesagility/SuiteCRM/
https://fluidattacks.com/advisories/silva/

Copyright 2026, cxsecurity.com

 

Back to Top