SuiteCRM: PHAR deserialization vulnerability to code execution
CYBERSECURITY FEATURED ANALYSIS

SuiteCRM: PHAR deserialization vulnerability to code execution

SOURCE

Blog RSS Feed | Snyk

DATE

READ

1 min read

This advisory details a PHAR deserialization vulnerability that exists in SuiteCRM which could be leveraged by an authenticated administrator to execute commands on the underlying operating system.

This advisory details a PHAR deserialization vulnerability that exists in SuiteCRM which could be leveraged by an authenticated administrator to execute commands on the underlying operating system.