PT-2023-32533 · Salesagility · Suitecrm

CVE-2023-6127

·

Publicado

2023-11-14

·

Atualizado

2024-03-06

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SuiteCRM versions prior to 7.14.2 SuiteCRM versions prior to 7.12.14 SuiteCRM versions prior to 8.4.2
Description The issue is related to the unrestricted upload of files with dangerous types in the GitHub repository salesagility/suitecrm.
Recommendations For versions prior to 7.14.2, update to version 7.14.2 or later. For versions prior to 7.12.14, update to version 7.12.14 or later. For versions prior to 8.4.2, update to version 8.4.2 or later.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-SUITECRM-2023-6127
CVE-2023-6127

Produtos afetados

Suitecrm