PT-2021-16884 · Suitecrm · Suitecrm
Published
2021-09-29
·
Updated
2024-03-06
·
CVE-2021-25960
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SuiteCRM versions 7.10.29 through 7.10.31
SuiteCRM versions 7.11.18 through 7.11.19
Description
The issue concerns a CSV Injection vulnerability, also known as Formula Injection, which allows a low-privileged attacker to inject payloads into input fields within the accounts module. When an administrator accesses this module to export data as a CSV file and opens it, the payload is executed. This vulnerability was not properly fixed as part of a previous security measure, enabling attackers to bypass security controls.
Recommendations
For SuiteCRM versions 7.10.29 through 7.10.31, consider disabling the export functionality in the accounts module until a proper fix is available.
For SuiteCRM versions 7.11.18 through 7.11.19, restrict access to the accounts module to minimize the risk of exploitation, especially when exporting data as CSV files.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suitecrm