Vulnerability Description
Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) picklist_name parameter in the get_picklists method to soap/customerportal.php, (2) where parameter in the get_tickets_list method to soap/customerportal.php, or (3) emailaddress parameter in the SearchContactsByEmail method to soap/vtigerolservice.php; or remote authenticated users to execute arbitrary SQL commands via the (4) emailaddress parameter in the SearchContactsByEmail method to soap/thunderbirdplugin.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vtiger | Vtiger Crm | 5.0.0 |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/bugtraq/2013-08/0001.htmlExploit
- http://karmainsecurity.com/KIS-2013-06Exploit
- http://www.securityfocus.com/bid/61563
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86129
- https://www.vtiger.com/blogs/?p=1467
- http://archives.neohapsis.com/archives/bugtraq/2013-08/0001.htmlExploit
- http://karmainsecurity.com/KIS-2013-06Exploit
- http://www.securityfocus.com/bid/61563
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86129
- https://www.vtiger.com/blogs/?p=1467
FAQ
What is CVE-2013-3213?
CVE-2013-3213 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) picklist_name parameter in the get_picklists method to soa...
How severe is CVE-2013-3213?
CVE-2013-3213 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-3213?
Check the references section above for vendor advisories and patch information. Affected products include: Vtiger Vtiger Crm.