SuiteCRM before 7.11.17 is vulnerable to remote code...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Nov 6, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 29, 2023
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.
References