peter bassill · operator
$ cve CVE-2009-3248 JSON

CVE-2009-3248 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 1.3% (pctl 69)

Patch early

A public exploit exists.

Description

Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin users for requests that modify the news feed system via the rssurl parameter in a Save action to index.php.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS1.26% — more likely to be exploited than 69% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2009-09-18
Last modified2026-06-16

Affected (1)

VendorProduct
vtigervtiger crm

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD