← Vulnerability feed

Vulnerability record · CVE-2020-28328 · published 6 November 2020

CVE-2020-28328: SuiteCRM log file name setting allows remote code execution

SSalesagility · Suitecrm

SuiteCRM before 7.11.17 lets an authenticated user with admin rights set the system Log File Name (logger_file_name) to point at an attacker-controlled .php file under the web root. Because the application then writes log data into that file, the attacker can place executable PHP content and run it, turning a configuration setting into remote code execution. The flaw matters because it converts a low-privilege foothold into full server compromise.

8.8 CVSS 3.1 High EPSS 63% · top 0.8% CWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score, v2 9.0
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityRemote code execution with public exploit code and very high EPSS, but it requires admin-level access or account takeover, so it is not trivially unauthenticated.

What it is

SuiteCRM before 7.11.17 lets an authenticated user with admin rights set the system Log File Name (logger_file_name) to point at an attacker-controlled .php file under the web root. Because the application then writes log data into that file, the attacker can place executable PHP content and run it, turning a configuration setting into remote code execution. The flaw matters because it converts a low-privilege foothold into full server compromise.

Impact

An attacker gains arbitrary code execution on the SuiteCRM host, leading to full compromise of confidentiality, integrity and availability of the application and its data.

Attack surface

Reached over the network through the SuiteCRM administrative system settings interface; the CVSS vector indicates low privileges (PR:L) and no user interaction (UI:N), and the description notes it requires admin account takeover or admin access.

Exploitation

Public exploit code is available (multiple Packet Storm and GitHub references tagged Exploit), and EPSS is high at 0.63 (99th percentile), though the CVE is not listed in CISA KEV.

What to do

  • Upgrade SuiteCRM to 7.11.17 or later (or the corresponding 7.10.28 LTS release) as the vendor advisory states.
  • Restrict admin accounts and enforce strong authentication and MFA to prevent the admin account takeover the exploit depends on.
  • Ensure the web root is not writable by the web server user and that log files cannot be created as .php under it.
  • Monitor and restrict changes to the logger_file_name system setting.
  • Apply least privilege to SuiteCRM service accounts and limit outbound and lateral movement from the host.

Detection

  • Alert on changes to the logger_file_name setting in SuiteCRM configuration or database.
  • Hunt for newly created .php files under the web root, especially ones containing log-formatted content.
  • Monitor web server logs for requests to unexpected .php paths that match log file names.
  • Watch for suspicious admin logins or privilege changes preceding configuration edits.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-28328 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-36412Salesagility suitecrm sql injection vulnerabilitySuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events…EPSS 5.7%9.8CVE-2023-6126Salesagility suitecrm code injection vulnerabilityCode Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.EPSS 0.69%9.8CVE-2021-45898Salesagility suitecrm vulnerabilitySuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.EPSS 1.1%9.8CVE-2021-45899Salesagility suitecrm deserialization of untrusted data vulnerabilitySuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.EPSS 2.2%9.8CVE-2020-8783Salesagility suitecrm sql injection vulnerabilitySuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4).EPSS 1.1%9.8CVE-2020-8784Salesagility suitecrm sql injection vulnerabilitySuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4).EPSS 1.1%9.8CVE-2020-8785Salesagility suitecrm sql injection vulnerabilitySuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4).EPSS 1.1%9.8CVE-2020-8786Salesagility suitecrm sql injection vulnerabilitySuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4).EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2020-28328), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.