Unrestricted file upload vulnerability in fileupload.html in vtiger CRM 4.2.4, and possibly earlier versions, allows remote attackers to upload and execute arbitrary files with executable extensions in the /cashe/mails folder.
| Software | From | Fixed in |
|---|---|---|
| vtiger / vtiger_crm | - | 4.2.4.x |