First published: Tue Sep 21 2021(Updated: )
In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). A low privileged attacker can use accounts module to inject payloads in the input fields. When an administrator access accounts module to export the data as a CSV file and opens it, the payload gets executed. This was not fixed properly as part of CVE-2020-15301, allowing the attacker to bypass the security measure.
Credit: vulnerabilitylab@mend.io
Affected Software | Affected Version | How to fix |
---|---|---|
SugarCRM | >=7.10.29<7.10.32 | |
SugarCRM | >=7.11.18<7.11.21 |
Update to v7.10.32 or v7.11.21
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25960 is a CSV Injection vulnerability (Formula Injection) in the SuiteCRM application.
CVE-2021-25960 affects SuiteCRM versions v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31.
CVE-2021-25960 has a severity level of high (8 out of 10).
A low privileged attacker can use the accounts module in SuiteCRM to inject payloads in the input fields.
Yes, you can find references for CVE-2021-25960 at the following links: [GitHub commit 1](https://github.com/salesagility/SuiteCRM/commit/7124482fe07ee164923d974456ed31e45f65e513), [GitHub commit 2](https://github.com/salesagility/SuiteCRM/commit/f463031bee59676d7d5be53bb32d551cd70a5648), [WhiteSource Software](https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25960).