CVE-2013-5091
Summary
| CVE | CVE-2013-5091 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-10-04 20:55:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated users to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php. NOTE: this issue might be a duplicate of CVE-2011-4559. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vtiger | Vtiger Crm | 1.0 | All | All | All |
| Application | Vtiger | Vtiger Crm | 2.0 | All | All | All |
| Application | Vtiger | Vtiger Crm | 2.0.1 | All | All | All |
| Application | Vtiger | Vtiger Crm | 2.1 | All | All | All |
| Application | Vtiger | Vtiger Crm | 3.0 | All | All | All |
| Application | Vtiger | Vtiger Crm | 3.0 | beta | All | All |
| Application | Vtiger | Vtiger Crm | 3.2 | All | All | All |
| Application | Vtiger | Vtiger Crm | 4 | All | All | All |
| Application | Vtiger | Vtiger Crm | 4 | beta | All | All |
| Application | Vtiger | Vtiger Crm | 4 | beta | All | it |
| Application | Vtiger | Vtiger Crm | 4 | rc1 | All | All |
| Application | Vtiger | Vtiger Crm | 4.0 | All | All | All |
| Application | Vtiger | Vtiger Crm | 4.0.1 | All | All | All |
| Application | Vtiger | Vtiger Crm | 4.2 | All | All | All |
| Application | Vtiger | Vtiger Crm | 4.2 | All | All | All |
| Application | Vtiger | Vtiger Crm | 4.2 | patch1 | All | All |
| Application | Vtiger | Vtiger Crm | 4.2.4 | All | All | All |
| Application | Vtiger | Vtiger Crm | 5.0.0 | All | All | All |
| Application | Vtiger | Vtiger Crm | 5.0.2 | All | All | All |
| Application | Vtiger | Vtiger Crm | 5.0.3 | All | All | All |
| Application | Vtiger | Vtiger Crm | 5.0.4 | All | All | All |
| Application | Vtiger | Vtiger Crm | 5.0.4 | rc | All | All |
| Application | Vtiger | Vtiger Crm | 5.1.0 | All | All | All |
| Application | Vtiger | Vtiger Crm | 5.1.0 | rc | All | All |
| Application | Vtiger | Vtiger Crm | 5.2.0 | All | All | All |
| Application | Vtiger | Vtiger Crm | 5.2.1 | All | All | All |
| Application | Vtiger | Vtiger Crm | 5.3.0 | All | All | All |
| Application | Vtiger | Vtiger Crm | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| osvdb.org/76138 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| File Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.htbridge.com | Third Party Advisory |
| Vtiger CRM - Browse /vtiger CRM 5.4.0/Core Product at SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | Patch, Third Party Advisory |
| Vtiger CRM 5.4.0 (index.php, onlyforuser param) - SQL Injection | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory |
| NEOHAPSIS - Peace of Mind Through Integrity and Insight | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.