CVE-2013-3215
CRITICALvtiger CRM <5.4.0 - Auth Bypass
Title source: llmDescription
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.
Exploits (2)
metasploit
WORKING POC
EXCELLENT
by Egidio Romano, juan vazquez · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/vtiger_soap_upload.rb
Scores
CVSS v3
9.8
EPSS
0.7367
EPSS Percentile
98.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-287
Status
published
Products (1)
vtiger/vtiger_crm
5.1.0 - 5.4.0
Published
Jan 29, 2020
Tracked Since
Feb 18, 2026