Description
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the RefreshMapping import functionality.
Related CPE's
a
salesagility
suitecrm
References
https://docs.suitecrm.com/admin/releases/7.10.x/#_7_10_33
https://docs.suitecrm.com/admin/releases/7.11.x/#_7_11_22
https://github.com/ach-ing/cves/blob/main/CVE-2021-41596.md
https://github.com/salesagility/SuiteCRM
https://docs.suitecrm.com/admin/releases/7.10.x/#_7_10_33
https://docs.suitecrm.com/admin/releases/7.11.x/#_7_11_22
https://github.com/ach-ing/cves/blob/main/CVE-2021-41596.md
https://github.com/salesagility/SuiteCRM
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
5.3 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2021-10-04T15:15:08.820Z
4 years agoLast modified
2024-11-21T05:26:30.177Z
1 year ago