A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature.
History

Tue, 10 Jun 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Vtiger
Vtiger vtiger Crm
CPEs cpe:2.3:a:vtiger:vtiger_crm:8.3.0:*:*:*:*:*:*:*
Vendors & Products Vtiger
Vtiger vtiger Crm

Thu, 22 May 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 21 May 2025 20:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-05-21T00:00:00.000Z

Updated: 2025-05-22T13:26:12.175Z

Reserved: 2025-04-22T00:00:00.000Z

Link: CVE-2025-45753

cve-icon Vulnrichment

Updated: 2025-05-22T13:26:04.427Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-21T21:16:03.403

Modified: 2025-06-10T19:34:41.410

Link: CVE-2025-45753

cve-icon Redhat

No data.