← Vulnerability feed

Vulnerability record · CVE-2021-42840 · published 22 October 2021

CVE-2021-42840: SuiteCRM log file name setting allows remote code execution

SSalesagility · Suitecrm

SuiteCRM before 7.11.19 lets an authenticated user set the Log File Name (logger_file_name) to a PHP file under the web root, because the blocklist only covered all-lowercase PHP extensions. This is an incomplete fix for CVE-2020-28328, so the earlier patch can be bypassed and code execution achieved.

8.8 CVSS 3.1 High EPSS 59% · top 0.9% CWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score, v2 9.0
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP file extensions were blocked. NOTE: this issue exists because of an incomplete fix for CVE-2020-28328.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 8.8 with a very high EPSS score and public exploit code, though exploitation requires an authenticated position and is not in KEV.

What it is

SuiteCRM before 7.11.19 lets an authenticated user set the Log File Name (logger_file_name) to a PHP file under the web root, because the blocklist only covered all-lowercase PHP extensions. This is an incomplete fix for CVE-2020-28328, so the earlier patch can be bypassed and code execution achieved.

Impact

An attacker who can reach the vulnerable setting gains remote code execution on the SuiteCRM host, with high impact to confidentiality, integrity and availability. The description notes this occurs in certain circumstances involving admin account takeover.

Attack surface

Reached over the network through the SuiteCRM web interface by an authenticated user with access to system settings; no user interaction is required per the CVSS vector (AV:N/AC:L/PR:L/UI:N). The record does not state exactly which privilege level is needed beyond the admin account takeover caveat.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.58945, 99th percentile) and public exploit references exist, including Packet Storm and a Metasploit module, indicating working exploit code is available.

What to do

  • Upgrade SuiteCRM to 7.11.19 or later (or the corresponding 7.10.30 LTS release) as the vendor advises.
  • Restrict access to system settings and admin functionality to trusted accounts and networks.
  • Enforce a strict allowlist for log file names and extensions rather than a lowercase-only blocklist.
  • Store logs outside the web root and ensure the web server cannot execute files in log or upload directories.
  • Audit for and remove any attacker-planted PHP files under the web root.

Detection

  • Review SuiteCRM logs and configuration changes for modifications to logger_file_name or the Log File Name setting.
  • Hunt for newly created or modified PHP files in web-accessible directories, especially those matching log file names.
  • Monitor web server logs for requests to unexpected PHP files under the web root.
  • Alert on SuiteCRM admin account activity that precedes file creation or configuration changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-42840 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-36412Salesagility suitecrm sql injection vulnerabilitySuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events…EPSS 5.7%9.8CVE-2023-6126Salesagility suitecrm code injection vulnerabilityCode Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.EPSS 0.69%9.8CVE-2021-45898Salesagility suitecrm vulnerabilitySuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.EPSS 1.1%9.8CVE-2021-45899Salesagility suitecrm deserialization of untrusted data vulnerabilitySuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.EPSS 2.2%9.8CVE-2020-8783Salesagility suitecrm sql injection vulnerabilitySuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4).EPSS 1.1%9.8CVE-2020-8784Salesagility suitecrm sql injection vulnerabilitySuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4).EPSS 1.1%9.8CVE-2020-8785Salesagility suitecrm sql injection vulnerabilitySuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4).EPSS 1.1%9.8CVE-2020-8786Salesagility suitecrm sql injection vulnerabilitySuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4).EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2021-42840), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.