SuiteCRM prior to 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the file_name parameter of the Step3 import functionality.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
salesagility suitecrm |