SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.
| Software | From | Fixed in |
|---|---|---|
| salesagility / suitecrm | 7.10.0 | 7.10.35 |
| salesagility / suitecrm | 7.12 | 7.12.2 |