PT-2014-4595 · Vtiger · Vtiger

Published

2014-11-16

·

Updated

2017-11-20

·

CVE-2014-2268

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions vTiger versions 6.0 before Security Patch 2
Description The issue is related to improper access restriction in the views/Index.php file within the Install module. This allows remote attackers to re-install the application by setting the X-Requested-With HTTP header in a request. Attackers can execute arbitrary PHP code via the db name parameter.
Recommendations For versions 6.0 before Security Patch 2, apply Security Patch 2 to resolve the issue. As a temporary workaround, consider restricting access to the views/Index.php file in the Install module to minimize the risk of exploitation. Avoid using the db name parameter in affected requests until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-2268

Affected Products

Vtiger