PT-2017-6895 · Salesagility · Suitecrm

Darren Martyn

·

Published

2017-08-07

·

Updated

2017-08-15

·

CVE-2015-5946

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SuiteCRM version 7.2.2
Description The issue allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension due to an incomplete blacklist vulnerability.
Recommendations For SuiteCRM version 7.2.2, update to a version that includes a comprehensive blacklist to prevent the upload of files with executable extensions.

Exploit

Fix

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-5946

Affected Products

Suitecrm