CVE-2021-42840
Last modified
CVE-2021-42840 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP file extensions were blocked. EPSS estimates a 58.95% chance of exploitation in the next 30 days.
Description
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP file extensions were blocked. NOTE: this issue exists because of an incomplete fix for CVE-2020-28328.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Salesagility | Suitecrm | < 7.11.19 |
References
- http://packetstormsecurity.com/files/165001/SuiteCRM-7.11.18-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://docs.suitecrm.com/admin/releases/7.11.x/#_7_11_19Release Notes, Vendor Advisory
- https://suitecrm.com/time-to-upgrade-suitecrm-7-11-19-7-10-30-lts-released/Release Notes, Vendor Advisory
- https://theyhack.me/SuiteCRM-RCE-2/Exploit, Third Party Advisory
- http://packetstormsecurity.com/files/165001/SuiteCRM-7.11.18-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://docs.suitecrm.com/admin/releases/7.11.x/#_7_11_19Release Notes, Vendor Advisory
- https://suitecrm.com/time-to-upgrade-suitecrm-7-11-19-7-10-30-lts-released/Release Notes, Vendor Advisory
- https://theyhack.me/SuiteCRM-RCE-2/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-42840?
How severe is CVE-2021-42840?
How do I fix CVE-2021-42840?
Are you affected by CVE-2021-42840?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
