CVE-2016-1713
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows remote authenticated users to execute arbitrary code by uploading a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.6%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows remote authenticated users to execute arbitrary code by uploading a crafted image file with an executable extension, then accessing it via a direct request to the file in test/logo/. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6000.
- CVSS 3.0
- 7.3 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 16.56% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- vtiger/vtiger crm
- Source
- cve@mitre.org
References
- http://b.fl7.de/2016/01/vtiger-crm-6.4-auth-rce.htmlExploit, Technical Description, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/01/12/4Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/01/12/7Mailing List
- https://www.exploit-db.com/exploits/44379/
- http://b.fl7.de/2016/01/vtiger-crm-6.4-auth-rce.htmlExploit, Technical Description, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/01/12/4Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/01/12/7Mailing List
- https://www.exploit-db.com/exploits/44379/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.