SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15301
Reference (s):
- https://www.wizlynxgroup.com/security-research-advisories/vuln/WLX-2020-010