283 software vendors have fixed 921 vulnerabilities in their products thanks to High-Tech Bridge Security Research Lab.
Patch Available Upon Disclosure
|2013 Q4: 67%||2013 Q1: 100%|
|2013 Q3: 77%||2012 Q4: 68%|
|2013 Q2: 92%||2012 Q3: 69%|
Vendor Average Time to Patch
|2013 Q4: 8 days||2013 Q1: 13 days|
|2013 Q3: 13 days||2012 Q4: 26 days|
|2013 Q2: 30 days||2012 Q3: 22 days|
SQL Injection in vtiger CRM
|Vulnerable Versions:||5.4.0 and probably prior|
|Advisory Publication:||August 7, 2013 [without technical details]|
|Vendor Notification:||August 7, 2013|
|Vendor Fix:||September 17, 2013|
|Public Disclosure:||September 18, 2013|
|Latest Update:||September 23, 2013|
|Vulnerability Type:||SQL Injection [CWE-89]|
|CVSSv2 Base Score:||6.5 (AV:N/AC:L/Au:S/C:P/I:P/A:P)|
|Solution Status:||Fixed by Vendor|
|Discovered and Provided:||High-Tech Bridge Security Research Lab|
High-Tech Bridge Security Research Lab discovered SQL injection vulnerability in vtiger CRM, which can be exploited to execute arbitrary SQL commands in application's database.
The vulnerability exists due to insufficient validation of "onlyforuser" HTTP GET parameter passed to "/index.php" script. A remote authenticated user can execute arbitrary SQL commands in application's database.
The following exploitation example displays version of MySQL server:
http://[host]/index.php?action=index&day=22&hour=0&module=Calendar&month=7&onlyforuser=1%20%20UNION% 20SELECT%201,2,3,4,5,6,version%28%29,8,9,10,11,12,13,14,15,16,17,18,19,20,1,22,23,24,25,26,27,28,29, 30,31,32%20--%20&parenttab=My%20Home%20Page&subtab=event&view=day&viewOption=hourview&year=2013
Successful exploitation of this vulnerability requires the attacker to be registered and logged-in. The registration is disabled by default.
Blind[!] SQL injection vulnerability in the same parameter of the vulnerable script was discovered in old version of vtiger CRM (5.2.1) on October 5, 2011 by Aung Khant: http://osvdb.org/76138
|Vendor has issued a fixed version of the vulnerable script "VtigerCRM540_Security_Patch2.zip" available for download at:|
| High-Tech Bridge Advisory HTB23168 - https://www.htbridge.com/advisory/HTB23168 - SQL Injection in vtiger CRM.|
 vtiger CRM - vtiger.com – vtiger CRM is an on demand customer relationship management software that provides sales, marketing, and support teams with powerful tools to efficiently and effectively collaborate in providing the ideal customer experience.
 Common Vulnerabilities and Exposures (CVE) - http://cve.mitre.org/ - international in scope and free for public use, CVE® is a dictionary of publicly known information security vulnerabilities and exposures.
 Common Weakness Enumeration (CWE) - http://cwe.mitre.org - targeted to developers and security practitioners, CWE is a formal list of software weakness types.
 ImmuniWeb® - is High-Tech Bridge's proprietary web application security assessment solution with SaaS delivery model that combines manual and automated vulnerability testing.
Please feel free to send us any additional information related to this Advisory, such as vulnerable versions, additional exploitation details and conditions, patches and other relevant details.