PT-2026-56208 · Unknown · Vtiger Crm
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Vtiger CRM versions prior to 8.4.1
Description
An authenticated remote code execution issue exists in the admin module import feature. Administrator-level attackers can upload arbitrary PHP files by submitting a crafted zip archive through the
ModuleManager import function. The system extracts contents directly into the modules/ directory under the web root without validating file types beyond the manifest.xml descriptor. This allows attackers to place executable PHP files in the modules/ directory that are directly accessible via HTTP, bypassing the authentication and authorization layer because the web server resolves the path and invokes the PHP interpreter before the application routing layer is involved, creating a persistent web shell.Recommendations
Update Vtiger CRM to a version newer than 8.4.0.
Restrict access to the
ModuleManager import function to minimize the risk of exploitation.Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vtiger Crm