
Ahmed Alshammari@ahmed_vapt
New CVE published: CVE-2026-71548 Sometimes you don't need to break the syntax, just go with it 🎯 Authenticated SQL injection in SuiteCRM's AOR_Reports module (High, CVSS 8.8). Any low-privileged user who can save a report could read the whole database, including the admin password hash. Fixed in 8.10.2 / 7.15.2 Advisory: https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-239h-ffjr-v957 Notes: https://docs.suitecrm.com/8.x/admin/releases/8.10/
00020446
10.1K followersView on X
