Description
VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.shielder.com/advisories/vtiger-mailmanager-sqli/ |
|
History
Fri, 16 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vtiger
Vtiger vtiger Crm |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:vtiger:vtiger_crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vtiger
Vtiger vtiger Crm |
|
| Metrics |
cvssV3_1
|
Fri, 16 Aug 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-16T17:58:59.527Z
Reserved: 2024-08-05T00:00:00.000Z
Link: CVE-2024-42994
Updated: 2024-08-16T17:58:53.238Z
Status : Analyzed
Published: 2024-08-16T17:15:15.153
Modified: 2025-04-28T14:10:13.853
Link: CVE-2024-42994
No data.
OpenCVE Enrichment
No data.
Weaknesses