Record summary

CVE-2020-28328 has a selected CVSS score of 8.8 (high); EIP currently links 2 catalogued exploits.

Description

SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBSuiteCRM 7.11.15 - 'last_name' Remote Code Execution (Authenticated)ExploitDB exploitby M. Cory BillingtonNot analyzed1 file
ExploitDB

PoC details
MetasploitSuiteCRM Log File Remote Code ExecutionMetasploit exploitby M. Cory BillingtonNot analyzed1 file

Ruby · linked to 3 vulnerabilities

Metasploit

PoC details

References

6