PoC Index

CVE-2011-4559

HIGH 7.5EPSS 1.3%

SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.34% chance of exploitation in the next 30 days, 69th percentile
Published
2011-11-28
Updated
2024-08-07

ExploitDB entries (1)

References

Related