Description
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:33:59.067Z
Reserved: 2020-11-06T00:00:00.000Z
Link: CVE-2020-28328
No data.
Status : Modified
Published: 2020-11-06T19:15:14.143
Modified: 2024-11-21T05:22:35.070
Link: CVE-2020-28328
No data.
OpenCVE Enrichment
No data.
Weaknesses