PT-2014-4595 · Vtiger · Vtiger
Published
2014-11-16
·
Updated
2017-11-20
·
CVE-2014-2268
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
vTiger versions 6.0 before Security Patch 2
Description
The issue is related to improper access restriction in the views/Index.php file within the Install module. This allows remote attackers to re-install the application by setting the X-Requested-With HTTP header in a request. Attackers can execute arbitrary PHP code via the
db name parameter.Recommendations
For versions 6.0 before Security Patch 2, apply Security Patch 2 to resolve the issue. As a temporary workaround, consider restricting access to the views/Index.php file in the Install module to minimize the risk of exploitation. Avoid using the
db name parameter in affected requests until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vtiger