CVE-2024-36416
SuiteCRM v4 API Excessive log data DOS
- Published
- Jun 10, 2024
- Updated
- Feb 13, 2025
- Assigning CNA
- GitHub_M
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HLow · next 30 days
- Percentile
- 79.1%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a deprecated v4 API example with no log rotation allows denial of service by logging excessive data. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
Sources
1- CVE-2024-36416Exploit
Python-based exploit validator for CVE-2024-36416 targeting SuiteCRM installations. Performs vulnerability detection, payload testing, and server-side log file analysis to confirm exploitation.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.