CVE-2023-46304

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
30/04/2024
Last modified:
22/04/2025

Description

modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vtiger:vtiger_crm:7.5.0:*:*:*:*:*:*:*