CVE-2020-15301
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Lead
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.
HIGH · CVSS 7.8
EPSS 0.00273
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0