Vulnerabilities > CVE-2020-8801 - Deserialization of Untrusted Data vulnerability in Salesagility Suitecrm

047910
CVSS 7.2 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
salesagility
CWE-502

Summary

SuiteCRM through 7.11.11 allows PHAR Deserialization.

Vulnerable Configurations

Part Description Count
Application
Salesagility
181

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/156324/KIS-2020-02.txt
idPACKETSTORM:156324
last seen2020-02-13
published2020-02-13
reporterEgiX
sourcehttps://packetstormsecurity.com/files/156324/SuiteCRM-7.11.11-Phar-Deserialization.html
titleSuiteCRM 7.11.11 Phar Deserialization