VendorsVtigervtiger_crm7.5.0
Vulnerabilities

Vtiger vtiger CRM 7.5.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2023-38891
SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.
Published 2023-09-14 · Modified
8.8EPSS 0.013
CVE-2023-46304
modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).
Published 2024-04-30 · Analyzed
8.1EPSS 0.017