Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jmcg-wx22-4gp4

Опубликовано: 30 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).

modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).

EPSS

Процентиль: 95%
0.20756
Средний

8.1 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 8.1
nvd
почти 2 года назад

modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).

EPSS

Процентиль: 95%
0.20756
Средний

8.1 High

CVSS3

Дефекты

CWE-74