SQL Injection in opportunities module in salesagility/suitecrm
Reported on
Oct 3rd 2023
Description
During the save of the the opportunity the duplicate_parent_id is not properly validated and cleaned, which allows for injecting sql.
Proof of Concept
Add sql injection statement to opportunities duplicate_parent_id on save request.
Impact
With SQL injection a user can read and manipulate data.
The Security Team have now assessed the following issue:
- SCRMBT-#240 - Opportunities Save - SQL injection
This issue has been given a severity grading of 'Important'.