Vtiger version 6.3.0 CRM's administration interface allows for the upload of a company logo. Instead of uploading an image, an attacker may choose to upload a file containing PHP code and run this code by accessing the resulting PHP file. This Metasploit module was tested against vTiger CRM version 6.3.0.
0e5c78b52a8faacfdb2de57265661b6c719a85c4847298f55630458f64d9b2ed
Vtiger CRM versions 6.3 and below suffer from an authenticated remote code execution vulnerability.
96b388a6a1d5f8b1624567791aa9ea216d7831e2fe9b587518ffa4e13d1e477c