Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-42840

Опубликовано: 22 окт. 2021
Источник: nvd
CVSS3: 8.8
CVSS2: 9
EPSS Средний

Описание

SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP file extensions were blocked. NOTE: this issue exists because of an incomplete fix for CVE-2020-28328.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*
Версия до 7.11.19 (исключая)

EPSS

Процентиль: 98%
0.49109
Средний

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-434

Связанные уязвимости

github
больше 3 лет назад

SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP file extensions were blocked. NOTE: this issue exists because of an incomplete fix for CVE-2020-28328.

EPSS

Процентиль: 98%
0.49109
Средний

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-434