CVE-2023-6388

Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the application is vulnerable to SSRF.
Configurations

Configuration 1 (hide)

cpe:2.3:a:salesagility:suitecrm:7.14.2:*:*:*:*:*:*:*

History

29 Sep 2025, 18:15

Type Values Removed Values Added
Summary (en) Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the application is vulnerable to SSRF. (en) Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the application is vulnerable to SSRF.
References
  • () https://docs.suitecrm.com/admin/releases/7.14.x/#_7_14_4 -

21 Nov 2024, 08:43

Type Values Removed Values Added
References () https://fluidattacks.com/advisories/leon/ - Exploit, Third Party Advisory () https://fluidattacks.com/advisories/leon/ - Exploit, Third Party Advisory
References () https://github.com/salesagility/SuiteCRM/ - Product () https://github.com/salesagility/SuiteCRM/ - Product

14 Feb 2024, 20:15

Type Values Removed Values Added
First Time Salesagility
Salesagility suitecrm
References () https://github.com/salesagility/SuiteCRM/ - () https://github.com/salesagility/SuiteCRM/ - Product
References () https://fluidattacks.com/advisories/leon/ - () https://fluidattacks.com/advisories/leon/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:salesagility:suitecrm:7.14.2:*:*:*:*:*:*:*

07 Feb 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-07 03:15

Updated : 2025-09-29 18:15


NVD link : CVE-2023-6388

Mitre link : CVE-2023-6388

CVE.ORG link : CVE-2023-6388


JSON object : View

Products Affected

salesagility

  • suitecrm
CWE
CWE-918

Server-Side Request Forgery (SSRF)