← Zurück zur CVE-Suche

CVE-2026-23698

Vtiger CRM

Beschreibung

Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleManager import function, which extracts contents directly into the modules/ directory under the web root without validating file types beyond the manifest.xml descriptor. Attackers can place executable PHP files in the modules/ directory that become directly accessible via HTTP, bypassing Vtiger-s authentication and authorization layer entirely since Apache resolves the path and invokes the PHP interpreter before the application routing layer is involved, resulting in a persistent web shell independent of the originating session.

CVSS 7.2EPSS 0.8670000000000001%Risiko 0.78
Quelle öffnen
Veröffentlicht
2026-07-07 17:16:36
Betroffene Versionen
<=8.4.0
Typ
Webanwendung
Vektor
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H