vendor:
Vtiger CRM
by:
Benjamin Daniel Mussler
8.8
CVSS
HIGH
Authenticated Remote Code Execution
79
CWE
Product Name: Vtiger CRM
Affected Version From: 6.3.2000
Affected Version To: 6.3.2000
Patch Exists: NO
Related CWE: CVE-2015-6000
CPE: a:vtiger:vtiger_crm:6.3.0
Platforms Tested: Linux
2015
Vtiger CRM <= 6.3.0 Authenticated Remote Code Execution
Vtiger CRM's administration interface allows for the upload of a company logo. Instead of uploading an image, an attacker may choose to upload a file containing PHP code and run this code by accessing the resulting PHP file.
Mitigation:
Upgrade to a version higher than 6.3.0