CVE-2023-1034
high · 8.8Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.
8.8
CVSS
28.1%
EPSS (exploit prob.)
98th
EPSS percentile
2023-02-25
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-29
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| salesagility | suitecrm | < 7.12.9 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/salesagility/suitecrm/commit/c19f221a41706efc8d73cef95c5e362c4f86bf06
- https://huntr.dev/bounties/0c1365bc-8d9a-4ae0-8b55-615d492b3730
- https://github.com/salesagility/suitecrm/commit/c19f221a41706efc8d73cef95c5e362c4f86bf06
- https://huntr.dev/bounties/0c1365bc-8d9a-4ae0-8b55-615d492b3730
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-1034