Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-38m6-xrq9-23c3

Опубликовано: 13 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.

SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.

EPSS

Процентиль: 63%
0.00437
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.

EPSS

Процентиль: 63%
0.00437
Низкий

Дефекты

CWE-352