9.9
CVE-2024-1644
- EPSS 0.86%
- Veröffentlicht 20.02.2024 00:15:14
- Zuletzt bearbeitet 31.12.2024 14:30:42
- Quelle help@fluidattacks.com
- CVE-Watchlists
- Unerledigt
Suite CRM v7.14.2 - RCE via Local File Inclusion
Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Salesagility ≫ Suite CRM Version7.14.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.86% | 0.536 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| help@fluidattacks.com | 9.9 | 3.1 | 6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
https://github.com/salesagility/SuiteCRM/
https://fluidattacks.com/advisories/silva/