漏洞描述 Vtiger CRM是美国Vtiger公司的一套基于SugarCRM开发的客户关系管理系统(CRM),它提供管理、收集、分析客户信息等功能。Install Module是其中的一个安装模块。 Vtiger CRM 6.0版本的Install模块中的views/Index.php脚本中存在安全漏洞,该漏洞源于程序没有正确限制访问权限。远程攻击者可通过发送包含X-Requested-With HTTP头设置的请求利用该漏洞重装应用程序。
相关漏洞推荐 POC vtigercrm-default-login: Vtiger CRM - Default Login POC vtigercrm-exposed-directory: Vtiger CRM - Exposed Directory wordpress-install: WordPress Exposed Installation POC CVE-2017-17736: Kentico - Installer Privilege Escalation POC CVE-2024-11972: Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation POC CVE-2024-9707: Hunk Companion <= 1.8.4 - Arbitrary Plugin Installation POC CVE-2018-0171: Cisco Smart Install - Configuration Download POC azure-vm-endpoint-protection-missing: Azure VM Endpoint Protection Not Installed POC avideo-install: AVideo Installer - Detect POC circarlife-installer: CirCarLife - Installer POC unsigned-kernel-mode-drivers-allowed: Installation of Unsigned Kernel-Mode Drivers Allowed POC windows-installer-elevated-privileges: Windows Installer Elevated Privileges Enabled POC windows-unsigned-drivers-allowed: Installation of Unsigned Drivers Allowed