Executive brief
Vtiger CRM, a popular customer relationship management platform, contains a security flaw in its administrative module import feature. An attacker with administrator-level credentials can upload a specially crafted file that installs a persistent 'web shell' on the server. This allows the attacker to execute arbitrary commands and take full control of the system, potentially leading to the theft of sensitive customer data or a complete service outage.
Technical details
An authenticated remote code execution (RCE) vulnerability exists in Vtiger CRM through version 8.4.0 due to unrestricted file uploads in the ModuleManager import function (CWE-434). Administrator-level attackers can submit a crafted ZIP archive containing arbitrary PHP files. The application extracts these files directly into the 'modules/' directory under the web root without validating file types beyond the manifest.xml descriptor. Because Apache resolves these paths and invokes the PHP interpreter before the application's routing or authentication layers are involved, the uploaded files can be accessed directly via HTTP. This results in a persistent web shell that remains active even after the attacker's session expires. While version 8.4.0 attempted to address related issues by updating a configuration template, the fix was not propagated to the installer or migration scripts, leaving many deployments vulnerable.
Affected products
- Vtiger Vtiger CRM through 8.4.0
Timeline
- 2026-07-07: disclosed: Initial disclosure by Jiva Security and VulnCheck
- 2026-07-07: advisory