CVE-2021-41596
04.10.2021, 17:15
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the RefreshMapping import functionality.
Vendor | Product | Version |
---|---|---|
salesagility | suitecrm | 𝑥 < 7.10.33 |
salesagility | suitecrm | 7.11.0 ≤ 𝑥 < 7.11.22 |
𝑥
= Vulnerable software versions
References