CRM
SuiteCRM/SuiteCRM
SuiteCRM - Open source CRM for the world
#crm#php#agplv3#accounts#contacts#workflow#reports#leads#quotes#opportunities#contracts#cases#portal#documents#multi-language-support#multi-currency#suitecrm
スコア
85
/ 100
Star
5,436
Fork
2,352
Open Issue
1,145
サイズ
144MB
言語
PHP ★
最終push
4 日前
Docker
—
採点内訳
過去CVE 20件 (やや多い)
✓直近 push: 4 日前
✓得意言語 (PHP)
✓オープンissue 1145件
✓大規模 (144MB)
—Docker 未対応
—1k–10k: 初心者ベスト (★5,436)
✓※ 各項目の重みは「採点ルール」を参照。合計は 0 で底打ち。
過去の SecurityAdvisory (20 件)
- Blind XSS in return_id parameter
- Remote Code Execution via Module Loader Package Scanner Bypass
- SuiteCRM Unauthenticated Open Redirect in Leads WebToLead Capture
- Authenticated Arbitrary File Upload via Configurator addfontresult View in SuiteCRM
- Authenticated RCE in Modules
- Directory Traversal to DoS in Modules
- Reflected HTML Injection in Login Page via default_user_name Parameter
- Authenticated Blind SQL Injection in OutboundEmail Legacy Functionality.
- Relative Path Traversal via ModuleBuilder Modules ExportCustom Action
- SuiteCRM Server-Side Request Forgery and Denial of Service via RSS Feed Dashlet
- Authenticated SQL Injection via unsanitized field_function in Report Fields
- REST API V8 IDOR: Missing ACL Checks on User Preferences and Relationship Endpoints
- LDAP Filter Injection in Authentication Module
- Authenticated SQL Injection in Authentication Module
- Unauthenticated reflected XSS in Login page
- Inconsistent RBAC Enforcement Enables Access Control Bypass [Project Task Creation/View Resource Calendar]
- Privilege Escalation in SuiteCRM-7.14.7 via Improper Session Invalidation and Inactive User Bypass
- Authenticated SQL Injection in Reschedule Call Module
- Improper Authorization on attachment downloads
- Reflected Cross Site Scripting (XSS) in SuiteCRM - HTTP Referer header