Medium severity5.3NVD Advisory· Published Oct 4, 2021· Updated Jun 17, 2026
CVE-2021-41595
CVE-2021-41595
Description
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the file_name parameter of the Step3 import functionality.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- SuiteCRM/SuiteCRMdescription
Patches
Vulnerability mechanics
References
3- docs.suitecrm.com/admin/releases/7.10.x/nvdRelease NotesVendor Advisory
- docs.suitecrm.com/admin/releases/7.11.x/nvdRelease NotesVendor Advisory
- github.com/ach-ing/cves/blob/main/CVE-2021-41595.mdnvdThird Party Advisory
News mentions
0No linked articles in our index yet.