PT-2020-14342 · Salesagility · Suitecrm

Luis Noriega

·

Published

2020-11-18

·

Updated

2024-03-06

·

CVE-2020-15301

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SuiteCRM versions prior to 7.11.14
Description The issue allows for CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. This occurs due to mishandling of these fields during a Download Import File Template operation.
Recommendations For versions prior to 7.11.14, update to version 7.11.14 or later to resolve the issue.

Fix

RCE

Weakness Enumeration

Related Identifiers

BIT-SUITECRM-2020-15301
CVE-2020-15301

Affected Products

Suitecrm