CVE-2020-28328 | SuiteCRM up to 7.11.16 File Name php logger_file_name access control (EDB-49001)
A vulnerability, which was classified as critical, was found in SuiteCRM up to 7.11.16. Affected is the function logger_file_name of the file php of the component File Name Handler. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2020-28328. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.