CVE-2026-29107 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, it is possible to…
Medium CVSS: 5.0

CVE-2026-29107

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, it is possible to create PDF templates with `<img>` tags. When a PDF is exported using this template, the content (for example, `<img src=http://{burp_collaborator_url}>` is rendered server side, and thus a request is issued from the server, resulting in Server-Side Request Forgery. Versions 7.15.1 and 8.9.3 patch the issue.
Vendor
Suitecrm
Product
Suitecrm
CWE
CWE-918
Yayın Tarihi
2026-03-19 23:16:43
Güncelleme
2026-03-24 13:46:52
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar