CVE-2021-41596

Publication date

2021-10-04 16:48:19

Family

mitre

State

PUBLISHED

Description

SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the RefreshMapping import functionality.