Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-23697

Опубликовано: 07 июл. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extension denylist in config.inc.php which omits the .phar extension. The uploaded file is stored with its original .phar extension under the web-accessible storage directory, and a misconfigured .htaccess using Apache 2.2 syntax is silently ignored on Apache 2.4 deployments, allowing unauthenticated HTTP requests to directly execute the uploaded PHP payload.

EPSS

Процентиль: 51%
0.00758
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
github
27 дней назад

Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extension denylist in config.inc.php which omits the .phar extension. The uploaded file is stored with its original .phar extension under the web-accessible storage directory, and a misconfigured .htaccess using Apache 2.2 syntax is silently ignored on Apache 2.4 deployments, allowing unauthenticated HTTP requests to directly execute the uploaded PHP payload.

CVSS3: 8.8
fstec
5 месяцев назад

Уязвимость модуля Documents системы управления взаимоотношениями с клиентами vTiger CRM, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации, загружать произвольные файлы и выполнить произвольный код

EPSS

Процентиль: 51%
0.00758
Низкий

8.8 High

CVSS3

Дефекты

CWE-434