Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8hfg-c2jc-x92h

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.

SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.

EPSS

Процентиль: 50%
0.00273
Низкий

Дефекты

CWE-1236

Связанные уязвимости

CVSS3: 7.8
nvd
около 5 лет назад

SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.

EPSS

Процентиль: 50%
0.00273
Низкий

Дефекты

CWE-1236