Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9r34-9mhm-m59q

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Users module in vTiger CRM 4.2 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary file in the templatename parameter, which is passed to the eval function.

The Users module in vTiger CRM 4.2 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary file in the templatename parameter, which is passed to the eval function.

EPSS

Процентиль: 79%
0.012
Низкий

Связанные уязвимости

nvd
около 20 лет назад

The Users module in vTiger CRM 4.2 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary file in the templatename parameter, which is passed to the eval function.

EPSS

Процентиль: 79%
0.012
Низкий