CVE detail
CVE-2021-25960 — CVE-2021-25960
Published 2021-09-29 · Modified 2026-06-17 · Vendor salesagility · Product suitecrm · Source nvd
HIGH
severity
CVSS-derived band
0.0119
EPSS probability
exploitation probability, 30d
65.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). A low privileged attacker can use accounts module to inject payloads in the input fields. When an administrator access accounts module to export the data as a CSV file and opens it, the payload gets executed. This was not fixed properly as part of CVE-2020-15301, allowing the attacker to bypass the security measure.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References