First published: Thu Sep 14 2023(Updated: )
SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Vtiger Vtiger Crm | =7.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38891 is a SQL injection vulnerability in Vtiger CRM v.7.5.0 that allows a remote authenticated attacker to escalate privileges.
CVE-2023-38891 affects Vtiger CRM v.7.5.0.
CVE-2023-38891 has a severity keyword of 'high' and a severity value of 8.8.
An attacker can exploit CVE-2023-38891 by using the getQueryColumnsList function in ReportRun.php to execute SQL injection attacks.
Yes, a fix for CVE-2023-38891 is available in newer versions of Vtiger CRM. It is recommended to update to the latest version to mitigate the vulnerability.