CVE-2017-5219 is a critical path traversal vulnerability affecting SageCRM 7.x before 7.3 SP3. Attackers can exploit the Component Manager's file upload functionality by crafting a malicious zip file containing an empty .ecf file and a web shell. This allows arbitrary files to be extracted outside the intended directory, specifically into the SageCRM webroot. The vulnerability has a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low complexity, and potential for complete compromise of confidentiality, integrity, and availability with SYSTEM privileges. While there is no known active exploitation, public exploit code, or significant community discussion, the high FAUCET Risk Score of 84/100 indicates a substantial risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.3CPE matchmatch criteria | cpe:2.3:a:sagecrm:sagecrm:7.3:*:*:*:*:*:*:* | ||
7.3CPE matchmatch criteria | cpe:2.3:a:sagecrm:sagecrm:7.3:sp1:*:*:*:*:*:* | ||
7.3CPE matchmatch criteria | cpe:2.3:a:sagecrm:sagecrm:7.3:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.