First published: Wed Nov 18 2020(Updated: )
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SalesAgility SuiteCRM | <=7.11.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of the SuiteCRM CSV Injection vulnerability is CVE-2020-15301.
The SuiteCRM CSV Injection vulnerability allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.
The severity rating of the SuiteCRM CSV Injection vulnerability is high, with a severity value of 7.8.
SuiteCRM versions up to and including 7.11.13 are affected by the CSV Injection vulnerability.
The SuiteCRM CSV Injection vulnerability can be exploited by injecting malicious data into registration fields in the Accounts, Contacts, Opportunities, and Leads modules.