jselliott

2 exploits Active since Sep 2023
CVE-2023-38891 NOMISEC HIGH WRITEUP
Vtiger CRM <7.5.0 - Privilege Escalation
SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.
1 stars
CVSS 8.8
CVE-2023-46304 NOMISEC HIGH WRITEUP
vtiger CRM 7.5.0 - Authenticated Remote Code Execution via Config File Write
modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).
1 stars
CVSS 8.1