Description
modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).
Published: 2024-04-30
Score: 8.1 High
EPSS: 20.8% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 26 Feb 2026 13:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:vtiger:vtiger_crm:*:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Vtiger
Vtiger vtiger Crm
CPEs cpe:2.3:a:vtiger:vtiger_crm:7.5.0:*:*:*:*:*:*:*
Vendors & Products Vtiger
Vtiger vtiger Crm

Subscriptions

Vtiger Vtiger Crm
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T20:45:40.776Z

Reserved: 2023-10-22T00:00:00.000Z

Link: CVE-2023-46304

cve-icon Vulnrichment

Updated: 2024-08-02T20:45:40.776Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-30T13:15:46.763

Modified: 2025-04-22T17:53:58.067

Link: CVE-2023-46304

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses