ID:3699 - Exploit for Improper Authentication - CVE-2013-3215
Published: August 4, 2020
Vulnerability identifier: #VU33660
Vulnerability risk: High
CVE-ID: CVE-2013-3215
CWE-ID: CWE-287
Exploitation vector: Remote access
Vulnerable software:
Link to public exploit:
Vulnerability description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.
Remediation
Install update from vendor's website.