An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://docs.suitecrm.com/admin/releases/7.12.x/ | release notes |
https://github.com/Orange-Cyberdefense/CVE-repository/ | third party advisory exploit |
https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/poc_SuiteCRM.py | exploit |