14 Nov 2023
Vulnérabilité CVE-2023-6127 CVE Vulnerability
Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. (CVSS:5.4) (Last Update:2023-11-14 16:15:28)
Vulnerability Details :
Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Exploit prediction scoring system (EPSS) score for CVE-2023-6127
We don't have an EPSS score for this CVE yet EPSS FAQ
CVSS scores for CVE-2023-6127
Base Score | Base Severity | CVSS Vector | Exploitability Score | Impact Score | Source |
---|---|---|---|---|---|
5.4 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 2.3 | 2.7 | Cette adresse e-mail est protégée contre les robots spammeurs. Vous devez activer le JavaScript pour la visualiser. |
CWE ids for CVE-2023-6127
- The product allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment.Assigned by: Cette adresse e-mail est protégée contre les robots spammeurs. Vous devez activer le JavaScript pour la visualiser. (Secondary)
References for CVE-2023-6127
- https://github.com/salesagility/suitecrm/commit/54bc56c3bd9f1db75408db1c1d7d652c3f5f71e9 SuiteCRM 7.14.2 Release · salesagility/SuiteCRM@54bc56c · GitHub
- https://huntr.com/bounties/bf10c72b-5d2e-4c9a-9bd6-d77bdf31027d File Upload caused XSS (Import account) vulnerability found in suitecrm