---
cve: "CVE-2020-28328"
severity: "LOW"
cvss: 3.1
epss: "63.3%"
vendor: "n/a"
kev: false
exploited: false
published: "2020-11-06 18:18:05"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-22T22:17:22+02:00"
---

# CVE-2020-28328

> 3.1 LOW · 🧪 PoC

## Beschreibung

SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.

## Exploit-Evidenz

- [EDB-49001 — SuiteCRM 7.11.15 - 'last_name' Remote Code Execution (Authenticated)](https://www.exploit-db.com/exploits/49001)

## Patch verfügbar (OSV)

- c0b55748904fb2aeb15ae7ab2afcd9657ebcde74 (Commit)

## Referenzen

- <https://suitecrm.com/suitecrm-7-11-17-7-10-28-lts-versions-released/>
- <https://github.com/mcorybillington/SuiteCRM-RCE>
- <http://packetstormsecurity.com/files/159937/SuiteCRM-7.11.15-Remote-Code-Execution.html>
- <http://packetstormsecurity.com/files/162975/SuiteCRM-Log-File-Remote-Code-Execution.html>
- <http://packetstormsecurity.com/files/165001/SuiteCRM-7.11.18-Remote-Code-Execution.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2020-28328) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
