Description
Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.
Remediation
References
Related Vulnerabilities
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2044)
Drupal Core 7.x Security Bypass (7.0 - 7.90)
MySQL CVE-2024-21238 Vulnerability (CVE-2024-21238)
WordPress Plugin Featurific For WordPress 'snum' Parameter Cross-Site Scripting (1.6.2)
WordPress Plugin MC4WP:Mailchimp for WordPress Cross-Site Scripting (4.1.6)