---
cve: "CVE-2021-42840"
severity: "LOW"
cvss: 3.1
epss: "58.9%"
vendor: "n/a"
kev: false
exploited: false
published: "2021-10-22 19:15:08"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-20T18:52:25+02:00"
---

# CVE-2021-42840

> 3.1 LOW · 🧪 PoC

## Beschreibung

SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP file extensions were blocked. NOTE: this issue exists because of an incomplete fix for CVE-2020-28328.

## Exploit-Evidenz

- [EDB-50531 — SuiteCRM 7.11.18 - Remote Code Execution (RCE) (Authenticated) (Metasploit)](https://www.exploit-db.com/exploits/50531) ✅

## Patch verfügbar (OSV)

- 9cb957e4f41562eb44f6ce8c982e2a3c169fc951 (Commit)

## Referenzen

- <https://docs.suitecrm.com/admin/releases/7.11.x/#_7_11_19>
- <https://github.com/rapid7/metasploit-framework/commits/master/modules/exploits/linux/http/suitecrm_log_file_rce.rb>
- <https://suitecrm.com/time-to-upgrade-suitecrm-7-11-19-7-10-30-lts-released/>
- <https://theyhack.me/SuiteCRM-RCE-2/>
- <http://packetstormsecurity.com/files/165001/SuiteCRM-7.11.18-Remote-Code-Execution.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2021-42840) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
