vtiger CRM 'validateSession()' Authentication Bypass Vulnerability
BID:61559
CVE-2013-3215 |Info
vtiger CRM 'validateSession()' Authentication Bypass Vulnerability
| Bugtraq ID: | 61559 |
| Class: | Design Error |
| CVE: |
CVE-2013-3215 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 01 2013 12:00AM |
| Updated: | Jan 09 2014 12:40AM |
| Credit: | Egidio Romano |
| Vulnerable: |
vtiger vtiger CRM 5.3 vtiger vtiger CRM 5.2.1 vtiger vtiger CRM 5.2 vtiger vtiger CRM 5.1 vtiger vtiger CRM 5.0.4 vtiger vtiger CRM 5.0.3 vtiger vtiger CRM 5.0.4 RC |
| Not Vulnerable: | |
Discussion
vtiger CRM 'validateSession()' Authentication Bypass Vulnerability
vtiger CRM is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may aid in further attacks.
vtiger CRM 5.4.0 and prior are vulnerable.
vtiger CRM is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may aid in further attacks.
vtiger CRM 5.4.0 and prior are vulnerable.
Exploit / POC
vtiger CRM 'validateSession()' Authentication Bypass Vulnerability
The following metasploit exploit code is available:
The following metasploit exploit code is available:
Solution / Fix
vtiger CRM 'validateSession()' Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
vtiger CRM 'validateSession()' Authentication Bypass Vulnerability
References:
References:
- vtiger Homepage (vtiger)