Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4c2c-97pg-w9x9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.

SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.

EPSS

Процентиль: 98%
0.49533
Средний

Дефекты

CWE-434
CWE-74

Связанные уязвимости

CVSS3: 8.8
nvd
больше 5 лет назад

SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.

EPSS

Процентиль: 98%
0.49533
Средний

Дефекты

CWE-434
CWE-74