SuiteCRM through 7.11.11 allows PHAR Deserialization.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://suitecrm.com | product |
http://seclists.org/fulldisclosure/2020/Feb/4 | third party advisory mailing list |
http://packetstormsecurity.com/files/156324/SuiteCRM-7.11.11-Phar-Deserialization.html | vdb entry third party advisory |