7.5
CVSSv2

CVE-2013-3214

Published: 28/01/2020 Updated: 31/01/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

vtiger CRM 5.4.0 and previous versions contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vtiger vtiger crm

Exploits

--------------------------------------------------------------------------------- vtiger CRM <= 540 (customerportalphp) Two Local File Inclusion Vulnerabilities --------------------------------------------------------------------------------- [-] Software Link: wwwvtigercom/ [-] Affected Versions: [1] All versions from 510 to ...
## # This module requires Metasploit: http//metasploitcom/download # Current source: githubcom/rapid7/metasploit-framework ## require 'msf/core' require 'rexml/document' class Metasploit3 < Msf::Exploit::Remote Rank = ExcellentRanking include REXML include Msf::Exploit::Remote::HttpClient include Msf::Exploit::FileDropper ...

Github Repositories

CVE-2013-3214

CVE-2013-3214 vTiger 540 Arbitrary File Upload to Remote Code Execution