CVE detail
CVE-2014-2268 — CVE-2014-2268
Published 2014-11-16 · Modified 2026-06-17 · Vendor vtiger · Product vtiger_crm · Source nvd
UNKNOWN
severity
CVSS-derived band
0.3121
EPSS probability
exploitation probability, 30d
98.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-install the application via a request that sets the X-Requested-With HTTP header, as demonstrated by executing arbitrary PHP code via the db_name parameter.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References