packetstormsecurity.com
http://packetstormsecurity.com/files/159937/SuiteCRM-7.11.15-Remote-Code-Execution.html CVE-2020-28328
HIGH
SuiteCRM 7.11.15 - 'last_name' Remote Code Execution (Authenticated)
Record summary
CVE-2020-28328 has a selected CVSS score of 8.8 (high); EIP currently links 2 catalogued exploits.
Description
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBSuiteCRM 7.11.15 - 'last_name' Remote Code Execution (Authenticated)ExploitDB exploitby M. Cory BillingtonNot analyzed1 file
MetasploitSuiteCRM Log File Remote Code ExecutionMetasploit exploitby M. Cory BillingtonNot analyzed1 file
References
6packetstormsecurity.com
http://packetstormsecurity.com/files/162975/SuiteCRM-Log-File-Remote-Code-Execution.html packetstormsecurity.com
http://packetstormsecurity.com/files/165001/SuiteCRM-7.11.18-Remote-Code-Execution.html github.com
https://github.com/mcorybillington/SuiteCRM-RCE nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-28328 suitecrm.com
https://suitecrm.com/suitecrm-7-11-17-7-10-28-lts-versions-released