First published: Mon Oct 04 2021(Updated: )
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the RefreshMapping import functionality.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SalesAgility SuiteCRM | <7.10.33 | |
SalesAgility SuiteCRM | >=7.11.0<7.11.22 | |
<7.10.33 | ||
>=7.11.0<7.11.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41596 is a vulnerability in SuiteCRM that allows information disclosure via Directory Traversal.
CVE-2021-41596 affects SuiteCRM versions before 7.10.33 and 7.11.22.
The severity level of CVE-2021-41596 is medium, with a CVSS score of 5.3.
An attacker can exploit CVE-2021-41596 by partially including arbitrary files via the importFile parameter of the RefreshMapping import functionality.
To fix CVE-2021-41596, it is recommended to update SuiteCRM to version 7.10.33 or 7.11.22.