Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated users to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php. NOTE: this issue might be a duplicate of CVE-2011-4559.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Vtiger CRM ‘onlyforuser’ 参数SQL注入漏洞
Vulnerability Description
Vtiger CRM是美国Vtiger公司的一套基于SugarCRM开发的客户关系管理系统(CRM)。该管理系统提供管理、收集、分析客户信息等功能。 vTiger CRM 5.4.0及之前的版本中的CalendarCommon.php脚本中存在SQL注入漏洞,该漏洞源于程序没有充分过滤‘onlyforuser’参数传递到index.php脚本。远程经过授权的攻击者可利用该漏洞在数据库中执行任意SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A