Vulnerability Description
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vtiger | Vtiger Crm | <= 5.4.0 |
Related Weaknesses (CWE)
References
- http://www.exploit-db.com/exploits/27279ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/61560Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86162Third Party AdvisoryVDB Entry
- http://www.exploit-db.com/exploits/27279ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/61560Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86162Third Party AdvisoryVDB Entry
FAQ
What is CVE-2013-3212?
CVE-2013-3212 is a vulnerability with a CVSS score of 8.1 (HIGH). vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.
How severe is CVE-2013-3212?
CVE-2013-3212 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-3212?
Check the references section above for vendor advisories and patch information. Affected products include: Vtiger Vtiger Crm.