← back
CVE-2009-3248

CVE-2009-3248

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 1.3%
from disclosure to weapon0 days
Published on NVDSep 18
1st PoCAug 18
exploitation probability
1.3%top 33% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin users for requests that modify the news feed system via the rssurl parameter in a Save action to index.php.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.