CVE-2016-1713 is an unrestricted file upload vulnerability in Vtiger CRM 6.4.0, specifically within the CompanyDetailsSave.php module, allowing authenticated users to upload malicious image files with executable extensions. This vulnerability, an incomplete fix for CVE-2015-6000, has a CVSS score of 7.3 (High) and an EPSS score indicating it is more exploitable than 98% of all CVEs. An attacker can achieve remote code execution by uploading a crafted file and then directly accessing it. While not on the KEV list or actively exploited, public exploit modules for Metasploit and ExploitDB exist, demonstrating its exploitability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.4.0CPE matchmatch criteria | cpe:2.3:a:vtiger:vtiger_crm:6.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.