CVE-2010-3909
Summary
| CVE | CVE-2010-3909 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-11-26 20:00:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Incomplete blacklist vulnerability in config.template.php in vtiger CRM before 5.2.1 allows remote authenticated users to execute arbitrary code by using the draft save feature in the Compose Mail component to upload a file with a .phtml extension, and then accessing this file via a direct request to the file in the storage/ directory tree. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vtiger | Vtiger Crm | All | All | All | All |
| Application | Vtiger | Vtiger Crm | 1.0 | All | All | All |
| Application | Vtiger | Vtiger Crm | 2.0 | All | All | All |
| Application | Vtiger | Vtiger Crm | 2.0.1 | All | All | All |
| Application | Vtiger | Vtiger Crm | 2.1 | All | All | All |
| Application | Vtiger | Vtiger Crm | 3 | All | All | All |
| Application | Vtiger | Vtiger Crm | 3.0 | All | All | All |
| Application | Vtiger | Vtiger Crm | 3.0 | beta | All | All |
| Application | Vtiger | Vtiger Crm | 3.2 | All | All | All |
| Application | Vtiger | Vtiger Crm | 4 | All | All | All |
| Application | Vtiger | Vtiger Crm | 4 | beta | All | All |
| Application | Vtiger | Vtiger Crm | 4 | rc1 | All | All |
| Application | Vtiger | Vtiger Crm | 4.0 | All | All | All |
| Application | Vtiger | Vtiger Crm | 4.0.1 | All | All | All |
| Application | Vtiger | Vtiger Crm | 4.2 | All | All | All |
| Application | Vtiger | Vtiger Crm | 4.2 | All | validation | All |
| Application | Vtiger | Vtiger Crm | 4.2.4 | All | All | All |
| Application | Vtiger | Vtiger Crm | 5.0.0 | All | All | All |
| Application | Vtiger | Vtiger Crm | 5.0.2 | All | All | All |
| Application | Vtiger | Vtiger Crm | 5.0.3 | All | All | All |
| Application | Vtiger | Vtiger Crm | 5.0.4 | All | All | All |
| Application | Vtiger | Vtiger Crm | 5.0.4 | rc | All | All |
| Application | Vtiger | Vtiger Crm | 5.1.0 | All | All | All |
| Application | Vtiger | Vtiger Crm | 5.1.0 | rc | All | All |
| Application | Vtiger | Vtiger Crm | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| vtiger CRM Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| HelpMeNow | af854a3a-2127-422b-91ae-364da2661108 | wiki.vtiger.com | |
| www.ush.it/team/ush/hack-vtigercrm_520/vtigercrm_520.txt | af854a3a-2127-422b-91ae-364da2661108 | www.ush.it | |
| vtiger CRM 5.2.1 is released. | The Vtiger Blog | af854a3a-2127-422b-91ae-364da2661108 | vtiger.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.