PT-2020-20292 · Salesagility · Suitecrm

Egidio Romano

·

Published

2020-02-13

·

Updated

2024-03-06

·

CVE-2020-8803

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SuiteCRM versions prior to 7.11.12
Description The issue allows Directory Traversal, enabling the inclusion of arbitrary .php files within the webroot via the add to prospect list function.
Recommendations For SuiteCRM versions prior to 7.11.12, update to version 7.11.12 or later to resolve the issue.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BIT-SUITECRM-2020-8803
CVE-2020-8803

Affected Products

Suitecrm