Show plain JSON{"id": "CVE-2017-5219", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 10.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C", "authentication": "NONE", "integrityImpact": "COMPLETE", "accessComplexity": "LOW", "availabilityImpact": "COMPLETE", "confidentialityImpact": "COMPLETE"}, "acInsufInfo": false, "impactScore": 10.0, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}]}, "published": "2017-02-02T07:59:00.177", "references": [{"url": "http://research.aurainfosec.io/disclosures/sagecrm-CVE-2017-5219-CVE-2017-5218/", "tags": ["Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/bid/95968", "tags": ["Third Party Advisory", "VDB Entry"], "source": "cve@mitre.org"}, {"url": "http://research.aurainfosec.io/disclosures/sagecrm-CVE-2017-5219-CVE-2017-5218/", "tags": ["Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/95968", "tags": ["Third Party Advisory", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-22"}]}], "descriptions": [{"lang": "en", "value": "An issue was discovered in SageCRM 7.x before 7.3 SP3. The Component Manager functionality, provided by SageCRM, permits additional components to be added to the application to enhance provided functionality. This functionality allows a zip file to be uploaded, containing a valid .ecf component file, which will be extracted to the inf directory outside of the webroot. By creating a zip file containing an empty .ecf file, to pass file-validation checks, any other file provided in zip file will be extracted onto the filesystem. In this case, a web shell with the filename '..\\WWWRoot\\CustomPages\\aspshell.asp' was included within the zip file that, when extracted, traversed back out of the inf directory and into the SageCRM webroot. This permitted remote interaction with the underlying filesystem with the highest privilege level, SYSTEM."}, {"lang": "es", "value": "Se descubri\u00f3 un problema en SageCRM 7.x en versiones anteriores a 7.3 SP3. La funcionalidad de Component Manager, proporcionada por SageCRM, permite a\u00f1adir componentes adicionales a la aplicaci\u00f3n para mejorar la funcionalidad proporcionada. Esta funcionalidad permite cargar un archivo zip, que contiene un archivo de componente .ecf v\u00e1lido, que se extraer\u00e1 al directorio inf fuera del webroot. Al crear un archivo zip que contenga un archivo .ecf vac\u00edo, para pasar las comprobaciones de validaci\u00f3n de archivos, cualquier otro archivo proporcionado en archivo zip se extraer\u00e1 en el sistema de archivos. En este caso, se incluy\u00f3 un shell web con el nombre de archivo '.. \\WWWRoot\\CustomPages\\aspshell.asp' dentro del archivo zip que, al ser extra\u00eddo, se volv\u00eda al directorio inf y al webroot de SageCRM. Esto permiti\u00f3 la interacci\u00f3n remota con el sistema de archivos subyacente con el nivel de privilegio m\u00e1s alto, SYSTEM."}], "lastModified": "2025-04-20T01:37:25.860", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:sagecrm:sagecrm:7.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6DCCCD34-465A-4D2A-AB74-07E368CF98DC"}, {"criteria": "cpe:2.3:a:sagecrm:sagecrm:7.3:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D50B7DB0-52AB-46EC-AD32-375A5CCE3416"}, {"criteria": "cpe:2.3:a:sagecrm:sagecrm:7.3:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "85CD71BD-9F51-4FE3-8C66-706967996C54"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}