CVE-2005-3823

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/11/2005
Last modified:
03/04/2025

Description

The Users module in vTiger CRM 4.2 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary file in the templatename parameter, which is passed to the eval function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vtiger:vtiger_crm:*:*:*:*:*:*:*:* 4.2 (including)