← Späť na vyhľadávanie CVE

CVE-2026-23698

Vtiger CRM

Popis

Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleManager import function, which extracts contents directly into the modules/ directory under the web root without validating file types beyond the manifest.xml descriptor. Attackers can place executable PHP files in the modules/ directory that become directly accessible via HTTP, bypassing Vtiger-s authentication and authorization layer entirely since Apache resolves the path and invokes the PHP interpreter before the application routing layer is involved, resulting in a persistent web shell independent of the originating session.

CVSS 7.2EPSS 0.8670000000000001%Riziko 0.78
Zobraziť zdroj
Zverejnené
2026-07-07 17:16:36
Dotknuté verzie
<=8.4.0
Typ
Webová aplikácia
Vektor
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H