First published: Fri May 24 2019(Updated: )
modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Vtiger Vtiger Crm | =6.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10754 is a vulnerability in Vtiger CRM 6.5.0 that allows SQL injection via the contactidlist parameter in the modules/Calendar/Activity.php file.
CVE-2016-10754 has a severity score of 8.8 (high).
To fix CVE-2016-10754, you should update Vtiger CRM to a version that is not affected by this vulnerability.
Yes, you can find more information about CVE-2016-10754 in the following references: [Link 1](https://blog.ripstech.com/2016/vtiger-sql-injection/), [Link 2](https://demo.ripstech.com/projects/vtiger_6.5.0).
The CWE (Common Weakness Enumeration) of CVE-2016-10754 is 89, which refers to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection').