← Back

CVE-2010-3909

nvd nist
Published: Nov 26, 2010Modified: Apr 29, 2026

JSON object

Loading...
6.0
Vector
AV:N/AC:M/Au:S/C:P/I:P/A:P
Exploitability: 6.8 / Impact: 6.4
Source: NVD

Description

Incomplete blacklist vulnerability in config.template.php in vtiger CRM before 5.2.1 allows remote authenticated users to execute arbitrary code by using the draft save feature in the Compose Mail component to upload a file with a .phtml extension, and then accessing this file via a direct request to the file in the storage/ directory tree.

Affected (25)

Products: Vtiger: Vtiger Crm
1 product
Vtiger Crm
Configuration A
25 vulnerable
Vulnerable SoftwareAffected Versions
Vtiger
All versions
Up to 5.2.0
Version 1.0
Version 2.0.1
Version 2.0
Version 2.1
Version 3.0
Version 3.0 beta
Version 3.2
Version 3
Version 4.0.1
Version 4.0
Version 4.2.4
Version 4.2
Version 4.2
Version 4
Version 4 beta
Version 4 rc1
Version 5.0.0
Version 5.0.2
Version 5.0.3
Version 5.0.4
Version 5.0.4 rc
Version 5.1.0
Version 5.1.0 rc

References (10)

Timeline

No history available yet.