Release date: 2013-08-01
Updated on:
Affected Systems:
Vtiger CRM 5.3
Vtiger CRM 5.2.1
Vtiger CRM 5.2
Vtiger CRM 5.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 61559
CVE (CAN) ID: CVE-2013-3215
Vtiger CRM is a free open-source customer relationship management software.
The 'validatesession () 'function of vtiger CRM 5.4.0 is defined in multiple SOAP services. If the "sessionid" parameter is not correctly verified, it is compared with the $ server_sessionid variable for valid session IDs, the 'validatesession () 'function returns "null". If the session ID is 0, false, or null, "true" is returned ". Attackers exploit this vulnerability to bypass the authentication mechanism by calling the SOAP method without providing the "username" and "sessionid" parameters.
<* Source: Egidio Romano
Link: http://www.securityfocus.com/archive/1/527667
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Vtiger
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.vtiger.com/blogs? P = 1467