Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Victor Garcia

#18300of 53,635
14.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2022-11437
8.8
2022-01-12
Suitecrm · Suitecrm · CVE-2021-41597
**Name of the Vulnerable Software and Affected Versions** SuiteCRM versions 7.11.21 and earlier **Description** The issue allows for remote code execution via the UpgradeWizard functionality if a PHP file is included in a ZIP archive. This is made possible by a CSRF vulnerability. **Recommendations** For versions 7.11.21 and earlier, update to a version that contains a fix for this issue to prevent remote code execution. As a temporary workaround, consider restricting access to the UpgradeWizard functionality until a patch is available.
PT-2021-24310
6.1
2021-12-28
Bitnami · Suitecrm · CVE-2021-45903
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268.