CVE-2024-42994

VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module.
References
Link Resource
https://www.shielder.com/advisories/vtiger-mailmanager-sqli/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:vtiger:vtiger_crm:*:*:*:*:*:*:*:*

History

28 Apr 2025, 14:10

Type Values Removed Values Added
References () https://www.shielder.com/advisories/vtiger-mailmanager-sqli/ - () https://www.shielder.com/advisories/vtiger-mailmanager-sqli/ - Exploit, Third Party Advisory
First Time Vtiger
Vtiger vtiger Crm
CPE cpe:2.3:a:vtiger:vtiger_crm:*:*:*:*:*:*:*:*

19 Aug 2024, 13:00

Type Values Removed Values Added
Summary
  • (es) VTiger CRM &lt;= 8.1.0 no desinfecta adecuadamente la entrada del usuario antes de usarla en una declaración SQL, lo que genera una inyección de SQL en la operación "CompanyDetails" del módulo "MailManager".

16 Aug 2024, 18:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
CWE CWE-89

16 Aug 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-16 17:15

Updated : 2025-04-28 14:10


NVD link : CVE-2024-42994

Mitre link : CVE-2024-42994

CVE.ORG link : CVE-2024-42994


JSON object : View

Products Affected

vtiger

  • vtiger_crm
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')