peter bassill · operator
$ cve CVE-2019-5009 JSON

CVE-2019-5009 EXPLOIT

7.2
HIGH · CVSS 3.1 · EPSS 9.9% (pctl 95)

Patch early

A public exploit exists.

Description

Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and has a size of 150x40. One can put PHP code into the image; PHP code can be executed using "<? ?>" tags, as demonstrated by a CompanyDetailsSave action. This bypasses the bad-file-extensions protection mechanism. It is related to actions/CompanyDetailsSave.php, actions/UpdateCompanyLogo.php, and models/CompanyDetails.php.

Scoring

CVSS7.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS9.94% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploityes
Published2019-01-04
Last modified2026-06-17

Affected (1)

VendorProduct
vtigervtiger crm

Public exploits

SourceTitleDate
exploit-dbVtiger CRM 7.1.0 - Remote Code Execution2019-01-02

References

→ the Explorer  ·  watch your stack  ·  NVD