CVE-2013-3215

CRITICAL

vtiger CRM 5.1.0-5.4.0 - Authentication Bypass via Improper Session Validation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2013-3215. PoCs published by EgiX, Egidio Romano, juan vazquez, including Metasploit module exploits/multi/http/vtiger_soap_upload.

AI-analyzed exploit summary The document describes multiple vulnerabilities in vtiger CRM <= 5.4.0, including local file inclusion (LFI) and SQL injection (SQLi) flaws. It provides detailed technical analysis of the vulnerable code and exploitation conditions.

Description

vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.

Exploits (2)

exploitdb WRITEUP
by EgiX · textwebappsphp
https://www.exploit-db.com/exploits/27279

The document describes multiple vulnerabilities in vtiger CRM <= 5.4.0, including local file inclusion (LFI) and SQL injection (SQLi) flaws. It provides detailed technical analysis of the vulnerable code and exploitation conditions.

Classification
Writeup 100%
Attack Type
Sqli | Info Leak
Complexity
Moderate
Reliability
Theoretical
Target: vtiger CRM <= 5.4.0
No auth needed
Prerequisites: PHP < 5.3.4 for LFI · Valid session or authentication for some SQLi vectors
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Egidio Romano, juan vazquez · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/vtiger_soap_upload.rb

This Metasploit module exploits an authentication bypass and arbitrary file upload vulnerability in vTiger CRM via SOAP services. It uploads a malicious PHP file and executes it to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: vTiger CRM v5.4.0
No auth needed
Prerequisites: Network access to the vTiger CRM instance · SOAP service enabled
devstral-2 · analyzed Apr 24, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/61559
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/86163

Scores

CVSS v3 9.8
EPSS 0.7367
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
vtiger/vtiger_crm 5.1.0 - 5.4.0
Published Jan 29, 2020
Tracked Since Feb 18, 2026