NA

CVE-2023-46304

Published: 30/04/2024 Updated: 30/04/2024

Vulnerability Summary

modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated malicious user to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).

Github Repositories

Authenticated Remote Code Execution in in VTiger Open Source CRM v7.5

CVE-2023-46304 Authenticated Remote Code Execution in in VTiger Open Source CRM v75 Summary A vulnerability exists in the Users module in the current release of VTiger CRM Open Source version 750 which allows an authenticated attacker to write and execute arbitrary PHP code to configincphp Exploit Details When a user is authenticated in VTiger normally, it checks their se