Vulnerability record · CVE-2020-28328 · published 6 November 2020
CVE-2020-28328: SuiteCRM log file name setting allows remote code execution
SSalesagility · Suitecrm
SuiteCRM before 7.11.17 lets an authenticated user with admin rights set the system Log File Name (logger_file_name) to point at an attacker-controlled .php file under the web root. Because the application then writes log data into that file, the attacker can place executable PHP content and run it, turning a configuration setting into remote code execution. The flaw matters because it converts a low-privilege foothold into full server compromise.
Description
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with public exploit code and very high EPSS, but it requires admin-level access or account takeover, so it is not trivially unauthenticated.
What it is
SuiteCRM before 7.11.17 lets an authenticated user with admin rights set the system Log File Name (logger_file_name) to point at an attacker-controlled .php file under the web root. Because the application then writes log data into that file, the attacker can place executable PHP content and run it, turning a configuration setting into remote code execution. The flaw matters because it converts a low-privilege foothold into full server compromise.
Impact
An attacker gains arbitrary code execution on the SuiteCRM host, leading to full compromise of confidentiality, integrity and availability of the application and its data.
Attack surface
Reached over the network through the SuiteCRM administrative system settings interface; the CVSS vector indicates low privileges (PR:L) and no user interaction (UI:N), and the description notes it requires admin account takeover or admin access.
Exploitation
Public exploit code is available (multiple Packet Storm and GitHub references tagged Exploit), and EPSS is high at 0.63 (99th percentile), though the CVE is not listed in CISA KEV.
What to do
- Upgrade SuiteCRM to 7.11.17 or later (or the corresponding 7.10.28 LTS release) as the vendor advisory states.
- Restrict admin accounts and enforce strong authentication and MFA to prevent the admin account takeover the exploit depends on.
- Ensure the web root is not writable by the web server user and that log files cannot be created as .php under it.
- Monitor and restrict changes to the logger_file_name system setting.
- Apply least privilege to SuiteCRM service accounts and limit outbound and lateral movement from the host.
Detection
- Alert on changes to the logger_file_name setting in SuiteCRM configuration or database.
- Hunt for newly created .php files under the web root, especially ones containing log-formatted content.
- Monitor web server logs for requests to unexpected .php paths that match log file names.
- Watch for suspicious admin logins or privilege changes preceding configuration edits.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-28328 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-28328), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.