vendor:
vtiger CRM
by:
9.3
CVSS
CRITICAL
Local File Include
98
CWE
Product Name: vtiger CRM
Affected Version From: vtiger CRM 5.2.1
Affected Version To: vtiger CRM (unknown)
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
vtiger CRM Local File Include Vulnerability
An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the underlying computer; other attacks are also possible.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user-supplied input and properly validate and restrict access to files and directories.