First published: Fri Feb 07 2020(Updated: )
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Vtiger Vtiger Crm | =5.3.0 | |
Vtiger Vtiger Crm | =5.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2013-3591.
The severity of CVE-2013-3591 is high with a value of 8.8.
The affected software is vTiger CRM version 5.3 and 5.4.
CVE-2013-3591 is a vulnerability in vTiger CRM 5.3 and 5.4 that allows for arbitrary PHP code execution through the 'files' upload folder.
Yes, there is a known exploit for CVE-2013-3591. You can find the exploit at http://www.exploit-db.com/exploits/29319.