VulnerabilityModified
CVE-2021-41596
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal.
MEDIUM 5.3EPSS 1.83%
Does this matter?
Lower severity and a low EPSS score (1.83%). Track it; it rarely justifies an emergency change on its own.
Description
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the RefreshMapping import functionality.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.83% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- salesagility/suitecrm
- Source
- cve@mitre.org
References
- https://docs.suitecrm.com/admin/releases/7.10.x/#_7_10_33Release Notes, Vendor Advisory
- https://docs.suitecrm.com/admin/releases/7.11.x/#_7_11_22Release Notes, Vendor Advisory
- https://github.com/ach-ing/cves/blob/main/CVE-2021-41596.mdThird Party Advisory
- https://github.com/salesagility/SuiteCRMProduct, Third Party Advisory
- https://suitecrm.comVendor Advisory
- https://docs.suitecrm.com/admin/releases/7.10.x/#_7_10_33Release Notes, Vendor Advisory
- https://docs.suitecrm.com/admin/releases/7.11.x/#_7_11_22Release Notes, Vendor Advisory
- https://github.com/ach-ing/cves/blob/main/CVE-2021-41596.mdThird Party Advisory
- https://github.com/salesagility/SuiteCRMProduct, Third Party Advisory
- https://suitecrm.comVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.