CVE-2019-5009

HIGH

Vtiger CRM 7.1.0 - Code Injection

Title source: llm
STIX 2.1

Description

Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and has a size of 150x40. One can put PHP code into the image; PHP code can be executed using "<? ?>" tags, as demonstrated by a CompanyDetailsSave action. This bypasses the bad-file-extensions protection mechanism. It is related to actions/CompanyDetailsSave.php, actions/UpdateCompanyLogo.php, and models/CompanyDetails.php.

Exploits (1)

exploitdb WORKING POC
by AkkuS · pythonwebappsphp
https://www.exploit-db.com/exploits/46065

Scores

CVSS v3 7.2
EPSS 0.1290
EPSS Percentile 94.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (2)
vtiger/vtiger_crm 7.1.0 hotfix1
vtiger/vtiger_crm < 7.1.0
Published Jan 04, 2019
Tracked Since Feb 18, 2026