peter bassill · operator
$ cve CVE-2013-5091 JSON

CVE-2013-5091 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 1.2% (pctl 67)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated users to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php. NOTE: this issue might be a duplicate of CVE-2011-4559.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS1.19% — more likely to be exploited than 67% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2013-10-04
Last modified2026-06-16

Affected (1)

VendorProduct
vtigervtiger crm

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD