PT-2026-26442 · Suitecrm · Suitecrm

D3Dn0V4

·

Publicado

2026-03-19

·

Atualizado

2026-05-13

·

CVE-2026-29104

CVSS v3.1

2.7

Baixa

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SuiteCRM versions prior to 7.15.1 SuiteCRM versions prior to 8.9.3
Description SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, it contains an authenticated arbitrary file upload issue in the Configurator module. An authenticated administrator can bypass file type restrictions when uploading PDF font files, allowing arbitrary files with attacker-controlled filenames to be written to the server. While the upload directory is not directly web-accessible by default, this breaks security boundaries and may enable further attacks when combined with other issues or in certain deployment configurations.
Recommendations SuiteCRM versions prior to 7.15.1 should be updated to version 7.15.1 or later. SuiteCRM versions prior to 8.9.3 should be updated to version 8.9.3 or later.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-29104
GHSA-5HX9-CMMX-26P3

Produtos afetados

Suitecrm