{"id":"CVE-2021-41597","details":"SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.","aliases":["BIT-suitecrm-2021-41597"],"modified":"2026-08-27T08:40:42.198061Z","published":"2022-01-12T20:15:08.287Z","references":[{"type":"WEB","url":"https://suitecrm.com"},{"type":"ADVISORY","url":"https://docs.suitecrm.com/admin/releases/"},{"type":"ADVISORY","url":"https://docs.suitecrm.com/admin/releases/7.10.x/#_7_10_35"},{"type":"ADVISORY","url":"https://github.com/ach-ing/cves/blob/main/CVE-2021-41597.md"},{"type":"PACKAGE","url":"https://github.com/salesagility/SuiteCRM"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/SuiteCRM/SuiteCRM","events":[{"introduced":"c6bece6ab3acd29365f5fc663ba8f3cc359a986b"},{"fixed":"9cdfcfb7e04cec1f327e6ed853423b4fc038b4a7"},{"introduced":"a4afbded5514f64e11e9d4eaf995bfe96fda86c9"},{"fixed":"0201c36b1468a16eb89218e7c798cf0ce2adac5c"}],"database_specific":{"cpe":"cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.10.0"},{"fixed":"7.10.35"},{"introduced":"7.12"},{"fixed":"7.12.2"}],"source":"CPE_RANGE"}}],"versions":["v7.12.1","v7.10.34","v7.10.33","v7.12.0","v7.10.32","v7.10.31","v7.10.30","v7.10.29","v7.10.28","v7.10.27","v7.10.26","v7.10.23","v7.10.20","v7.10.17","v7.10.19","v7.10.18","v7.10.16","v7.10.15","v7.10.12","v7.10.14","v7.10.13","v7.10.11","v7.10.10","v7.10.5","v7.10.7","v7.10.4","v7.10.6","v7.10.1","v7.10.3","v7.10.2","v7.10.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41597.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}