216.73.216.133

CVE-2022-45185

· Published 07/01/2025 20:15 · Modified 08/01/2025 18:15

Labels: CVE-2022-45185 2025-01-07CVE-2022-45185CWE-502[email protected]

Essential information

Published
07/01/2025 20:15
Modified
08/01/2025 18:15
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.

NVD status

Status
Undergoing Analysis — CVE is currently being analyzed by NVD staff, this process results in association of reference link tags, CVSS scores, CWE association, and CPE applicability statements.
Source
[email protected]
NVD
View on NVD

References