CVE-2026-23697
- EPSS 1.07%
- Veröffentlicht 07.07.2026 16:17:02
- Zuletzt bearbeitet 08.07.2026 15:28:15
Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extensio...
CVE-2026-23698
- EPSS 0.87%
- Veröffentlicht 07.07.2026 16:10:24
- Zuletzt bearbeitet 08.07.2026 15:28:15
Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleMa...
CVE-2025-1618
- EPSS 0.39%
- Veröffentlicht 24.02.2025 05:15:10
- Zuletzt bearbeitet 29.01.2026 02:11:45
A vulnerability has been found in vTiger CRM 6.4.0/6.5.0 and classified as problematic. This vulnerability affects unknown code of the file /modules/Mobile/index.php. The manipulation of the argument _operation leads to cross site scripting. The atta...