modules/Users/models/Module.php in Vtiger CRM 7.5.0...
High severity
Unreviewed
Published
Apr 30, 2024
to the GitHub Advisory Database
•
Updated Jul 3, 2024
Description
Published by the National Vulnerability Database
Apr 30, 2024
Published to the GitHub Advisory Database
Apr 30, 2024
Last updated
Jul 3, 2024
modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).
References