Security Advisory

CVE-2021-42840

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-10-22 18:20:23
Last updated 2024-08-04 03:38:50
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP file extensions were blocked. NOTE: this issue exists because of an incomplete fix for CVE-2020-28328.