PT-2021-23357 · Suitecrm · Suitecrm

Published

2021-10-04

·

Updated

2024-03-06

·

CVE-2021-41595

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SuiteCRM versions prior to 7.10.33 SuiteCRM versions prior to 7.11.22
Description The issue allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the file name parameter of the Step3 import functionality.
Recommendations For versions prior to 7.10.33, update to version 7.10.33 or later. For versions prior to 7.11.22, update to version 7.11.22 or later. As a temporary workaround, consider restricting access to the Step3 import functionality until a patch is available. Avoid using the file name parameter in the affected import functionality until the issue is resolved.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BIT-SUITECRM-2021-41595
CVE-2021-41595

Affected Products

Suitecrm