First published: Mon Oct 04 2021(Updated: )
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the file_name parameter of the Step3 import functionality.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SalesAgility SuiteCRM | <7.10.33 | |
SalesAgility SuiteCRM | >=7.11.0<7.11.22 | |
<7.10.33 | ||
>=7.11.0<7.11.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41595 is a vulnerability in SuiteCRM before version 7.10.33 and 7.11.22 that allows information disclosure through Directory Traversal.
CVE-2021-41595 allows an attacker to partially include arbitrary files by manipulating the 'file_name' parameter of the Step3 import functionality.
CVE-2021-41595 has a severity rating of 5.3, which is considered medium.
SuiteCRM versions before 7.10.33 and 7.11.22 are affected by CVE-2021-41595.
To fix CVE-2021-41595, you should update SuiteCRM to version 7.10.33 or 7.11.22.