CVE-2023-46304
Last modified
CVE-2023-46304 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).. EPSS estimates a 1.66% chance of exploitation in the next 30 days.
Description
modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vtiger | Vtiger Crm | 7.5.0 |
References
- https://www.vtiger.com/Product
- https://www.vtiger.com/Product
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-46304?
How severe is CVE-2023-46304?
How do I fix CVE-2023-46304?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-46298Next.js before 13.4.20-canary.13 lacks a cache-control heade…7.5
- CVE-2023-4630An issue has been discovered in GitLab affecting all version…4.3
- CVE-2023-46300iTerm2 before 3.4.20 allow (potentially remote) code executi…9.8
- CVE-2023-46301iTerm2 before 3.4.20 allow (potentially remote) code executi…9.8
- CVE-2023-46302Apache Software Foundation Apache Submarine has a bug when s…9.8
- CVE-2023-46303link_to_local_path in ebooks/conversion/plugins/html_input.p…7.5
- CVE-2023-46306The web administration interface in NetModule Router Softwar…6.6
- CVE-2023-46307An issue was discovered in server.js in etcd-browser 87ae63d…7.5
- CVE-2023-46308In Plotly plotly.js before 2.25.2, plot API calls have a ris…9.8
- CVE-2023-46309Missing Authorization vulnerability in AdvancedCoding wpDisc…7.3
- CVE-2023-4631The DoLogin Security WordPress plugin before 3.7 uses header…5.3
- CVE-2023-46310Improper Neutralization of Script-Related HTML Tags in a Web…6.1
Are you affected by CVE-2023-46304?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
