SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.
| Software | From | Fixed in |
|---|---|---|
| salesagility / suitecrm | 8.0-rc | 8.0-rc.x |
| salesagility / suitecrm | 8.0-beta3 | 8.0-beta3.x |
| salesagility / suitecrm | 8.0-beta2 | 8.0-beta2.x |
| salesagility / suitecrm | 8.0-beta | 8.0-beta.x |
| salesagility / suitecrm | - | 7.12.2 |
| salesagility / suitecrm | 8.0.0 | 8.0.0.x |