CVE-2024-45392: Salesagility Suitecrm

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Versions 7.14.5 and 8.6.2 contain a patch for the issue.

Affected products

  • Salesagility Suitecrm: before 7.14.5 (fixed in 7.14.5); from 8.0.0, before 8.6.2 (fixed in 8.6.2)

Published 2024-09-05. Last modified 2026-06-17.