vendor:
CRM
by:
James Bercegay and Damon Wood of the GulfTech Security Research Team and Daniel Fabian of SEC-CONSULT
8.8
CVSS
HIGH
SQL injection, HTML injection, cross-site scripting and local file include
89, 79, 79, 22
CWE
Product Name: CRM
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
vtiger CRM Multiple Input Validation Vulnerabilities
An attacker can exploit these issues to gain administrative access, retrieve username and password pairs, steal cookie-based authentication credentials and retrieve arbitrary local files in the context of the Web server process; other attacks are also possible.
Mitigation:
Input validation and sanitization should be implemented to prevent these issues.