Input validation error in SuiteCRM - CVE-2019-18782
Published: March 20, 2020 / Updated: August 8, 2020
Vulnerability identifier: #VU34713
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-18782
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism.
Affected software
SuiteCRM
How to mitigate CVE-2019-18782
Install update from vendor's website.
SuiteCRM - update to 7.11.9