CVE-2014-2269

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
22/04/2014
Last modified:
12/04/2025

Description

modules/Users/ForgotPassword.php in vTiger 6.0 before Security Patch 2 allows remote attackers to reset the password for arbitrary users via a request containing the username, password, and confirmPassword parameters.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vtiger:vtiger_crm:6.0.0:*:*:*:*:*:*:*