SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the file_name parameter of the Step3 import functionality.
| Software | From | Fixed in |
|---|---|---|
| salesagility / suitecrm | 7.11.0 | 7.11.22 |
| salesagility / suitecrm | - | 7.10.33 |