VulnerabilityModified
CVE-2013-5091
SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated users to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php.
MEDIUM 6.5EPSS 1.19%
Does this matter?
Lower severity and a low EPSS score (1.19%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated users to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php. NOTE: this issue might be a duplicate of CVE-2011-4559.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.19% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- vtiger/vtiger crm
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2013-09/0079.htmlThird Party Advisory
- http://osvdb.org/76138Broken Link
- http://sourceforge.net/projects/vtigercrm/files/vtiger%20CRM%205.4.0/Core%20Product/Patch, Third Party Advisory
- http://www.exploit-db.com/exploits/28409Exploit, Third Party Advisory
- https://www.htbridge.com/advisory/HTB23168Third Party Advisory
- http://archives.neohapsis.com/archives/bugtraq/2013-09/0079.htmlThird Party Advisory
- http://osvdb.org/76138Broken Link
- http://sourceforge.net/projects/vtigercrm/files/vtiger%20CRM%205.4.0/Core%20Product/Patch, Third Party Advisory
- http://www.exploit-db.com/exploits/28409Exploit, Third Party Advisory
- https://www.htbridge.com/advisory/HTB23168Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.