Description
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:33:59.067Z
Reserved: 2020-11-06T00:00:00.000Z
Link: CVE-2020-28328
No data.
Status : Modified
Published: 2020-11-06T19:15:14.143
Modified: 2024-11-21T05:22:35.070
Link: CVE-2020-28328
No data.
OpenCVE Enrichment
No data.
Weaknesses