Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in test/logo/.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: certcc
Published: 2020-02-06T13:55:09
Updated: 2024-08-06T07:06:35.224Z
Reserved: 2015-08-14T00:00:00
Link: CVE-2015-6000
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-02-06T14:15:10.597
Modified: 2024-11-21T02:34:16.470
Link: CVE-2015-6000
Redhat
No data.