Vulnerability record · CVE-2021-42840 · published 22 October 2021
CVE-2021-42840: SuiteCRM log file name setting allows remote code execution
SSalesagility · Suitecrm
SuiteCRM before 7.11.19 lets an authenticated user set the Log File Name (logger_file_name) to a PHP file under the web root, because the blocklist only covered all-lowercase PHP extensions. This is an incomplete fix for CVE-2020-28328, so the earlier patch can be bypassed and code execution achieved.
Description
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP file extensions were blocked. NOTE: this issue exists because of an incomplete fix for CVE-2020-28328.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with a very high EPSS score and public exploit code, though exploitation requires an authenticated position and is not in KEV.
What it is
SuiteCRM before 7.11.19 lets an authenticated user set the Log File Name (logger_file_name) to a PHP file under the web root, because the blocklist only covered all-lowercase PHP extensions. This is an incomplete fix for CVE-2020-28328, so the earlier patch can be bypassed and code execution achieved.
Impact
An attacker who can reach the vulnerable setting gains remote code execution on the SuiteCRM host, with high impact to confidentiality, integrity and availability. The description notes this occurs in certain circumstances involving admin account takeover.
Attack surface
Reached over the network through the SuiteCRM web interface by an authenticated user with access to system settings; no user interaction is required per the CVSS vector (AV:N/AC:L/PR:L/UI:N). The record does not state exactly which privilege level is needed beyond the admin account takeover caveat.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.58945, 99th percentile) and public exploit references exist, including Packet Storm and a Metasploit module, indicating working exploit code is available.
What to do
- Upgrade SuiteCRM to 7.11.19 or later (or the corresponding 7.10.30 LTS release) as the vendor advises.
- Restrict access to system settings and admin functionality to trusted accounts and networks.
- Enforce a strict allowlist for log file names and extensions rather than a lowercase-only blocklist.
- Store logs outside the web root and ensure the web server cannot execute files in log or upload directories.
- Audit for and remove any attacker-planted PHP files under the web root.
Detection
- Review SuiteCRM logs and configuration changes for modifications to logger_file_name or the Log File Name setting.
- Hunt for newly created or modified PHP files in web-accessible directories, especially those matching log file names.
- Monitor web server logs for requests to unexpected PHP files under the web root.
- Alert on SuiteCRM admin account activity that precedes file creation or configuration changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-42840 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-42840), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.