CVE-2008-2689 describes a critical remote file inclusion vulnerability in BrowserCRM version 5.002.00, specifically within the pub/clients.php component. This flaw allows unauthenticated remote attackers to execute arbitrary PHP code by manipulating the 'bcrm_pub_root' parameter. The vulnerability carries a CVSS score of 10.0, indicating maximum severity with a network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. Its high EPSS and FAUCET Risk Score further emphasize the significant risk it poses. While not listed on the CISA KEV catalog or Hot List, exploit code for this vulnerability is publicly available on ExploitDB (EDB-5757). Despite its age and high severity, there is no recorded community discussion or media coverage, suggesting it may not be widely tracked or actively exploited in current environments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.002.00CPE matchmatch criteria | cpe:2.3:a:browsercrm:browsercrm:5.002.00:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.