7.5
CVSSv2

CVE-2013-3213

Published: 02/04/2014 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 up to and including 5.4.0 allow remote malicious users to execute arbitrary SQL commands via the (1) picklist_name parameter in the get_picklists method to soap/customerportal.php, (2) where parameter in the get_tickets_list method to soap/customerportal.php, or (3) emailaddress parameter in the SearchContactsByEmail method to soap/vtigerolservice.php; or remote authenticated users to execute arbitrary SQL commands via the (4) emailaddress parameter in the SearchContactsByEmail method to soap/thunderbirdplugin.php.

Vulnerable Product Search on Vulmon Subscribe to Product

vtiger vtiger crm 5.0.0

vtiger vtiger crm 5.4.0

vtiger vtiger crm 5.0.4

vtiger vtiger crm 5.0.1

vtiger vtiger crm 5.2.0

vtiger vtiger crm 5.1.0

vtiger vtiger crm 5.0.3

vtiger vtiger crm 5.3.0

vtiger vtiger crm 5.2.1

vtiger vtiger crm 5.0.2

Exploits

--------------------------------------------------------------------------------- vtiger CRM <= 540 (customerportalphp) Two Local File Inclusion Vulnerabilities --------------------------------------------------------------------------------- [-] Software Link: wwwvtigercom/ [-] Affected Versions: [1] All versions from 510 to ...