Lucene search

K
osvGoogleOSV:CVE-2021-41595
HistoryOct 04, 2021 - 5:15 p.m.

CVE-2021-41595

2021-10-0417:15:08
Google
osv.dev
7
suitecrm
vulnerability
information disclosure
directory traversal
step3 import
software

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

44.5%

SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the file_name parameter of the Step3 import functionality.

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

44.5%

Related for OSV:CVE-2021-41595