Логотип exploitDog
bind:CVE-2023-46304
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-46304

Количество 2

Количество 2

nvd логотип

CVE-2023-46304

почти 2 года назад

modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-jmcg-wx22-4gp4

почти 2 года назад

modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).

CVSS3: 8.1
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-46304

modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).

CVSS3: 8.1
21%
Средний
почти 2 года назад
github логотип
GHSA-jmcg-wx22-4gp4

modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).

CVSS3: 8.1
21%
Средний
почти 2 года назад

Уязвимостей на страницу