First published: Tue Nov 14 2023(Updated: )
Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
SalesAgility SuiteCRM | <7.12.14 | |
SalesAgility SuiteCRM | =7.14.0 | |
SalesAgility SuiteCRM | =7.14.1 | |
SalesAgility SuiteCRM | =8.4.0 | |
SalesAgility SuiteCRM | =8.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6130 is a vulnerability in the GitHub repository salesagility/suitecrm that allows for path traversal attacks.
The severity of CVE-2023-6130 is high, with a severity score of 8.8.
Versions prior to 7.14.2, 7.12.14, and 8.4.2 of SalesAgility SuiteCRM are affected by CVE-2023-6130.
To fix CVE-2023-6130, it is recommended to update to version 7.14.2, 7.12.14, or 8.4.2 of SalesAgility SuiteCRM.
More information about CVE-2023-6130 can be found at the following links: [Link 1](https://huntr.com/bounties/22a27be9-f016-4daf-9887-c77eb3e1dc74), [Link 2](https://github.com/salesagility/suitecrm/commit/54bc56c3bd9f1db75408db1c1d7d652c3f5f71e9).