Path Traversal: '\..\filename' in salesagility/suitecrm
CVE-2023-6130
7.5HIGH
What is CVE-2023-6130?
A path traversal vulnerability in SuiteCRM, developed by SalesAgility, poses a risk of unauthorized file access. This flaw allows an attacker to manipulate file paths, leading to potential exposure of sensitive data by accessing files located outside the intended directories. The vulnerability affects all versions of SuiteCRM prior to 7.14.2, 7.12.14, and 8.4.2. Users are advised to upgrade to the latest versions to mitigate potential risks.
Affected Version(s)
salesagility/suitecrm < 7.14.2, 7.12.14, 8.4.2