CVE-2023-46304
HIGH 8.1EPSS 1.7%
modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).
- CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 1.66% chance of exploitation in the next 30 days, 75th percentile
- Published
- 2024-04-30
- Updated
- 2024-08-02
Proof-of-concept exploits (1)
- jselliott/CVE-2023-463041★ · 2024-04-03