CVE-2010-3910
CVE-2010-3910 is a medium-severity vulnerability in Vtiger Vtiger Crm with a CVSS 2.0 base score of 6.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Medium (CVSS 2.0 base score 6.8)
- EPSS exploit prediction: 7% (94th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-22
- Affected product: Vtiger Vtiger Crm
- Published:
- Last modified:
Description
Multiple directory traversal vulnerabilities in the return_application_language function in include/utils/utils.php in vtiger CRM before 5.2.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lang_crm parameter to phprint.php or (2) the current_language parameter in an Accounts Import action to graph.php.
Frequently asked questions
- What is CVE-2010-3910?
- Multiple directory traversal vulnerabilities in the return_application_language function in include/utils/utils.php in vtiger CRM before 5.2.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lang_crm parameter to phprint.php or (2) the current_language parameter in an Accounts Import action to graph.php.
- How severe is CVE-2010-3910?
- CVE-2010-3910 has a CVSS 2.0 base score of 6.8, rated medium severity.
- Is CVE-2010-3910 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 7% (94th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2010-3910?
- CVE-2010-3910 primarily affects Vtiger Vtiger Crm. In total, 24 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2010-3910?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2010-3910 published?
- CVE-2010-3910 was published on 2010-11-26 and last updated on 2026-06-16.
References
- http://secunia.com/advisories/42246
- http://vtiger.com/blogs/2010/11/16/vtiger-crm-521-is-released/
- http://wiki.vtiger.com/index.php/Vtiger521:Release_Notes
- http://www.securityfocus.com/archive/1/514846/100/0/threaded
- http://www.ush.it/team/ush/hack-vtigercrm_520/vtigercrm_520.txt
Affected products (24)
- cpe:2.3:a:vtiger:vtiger_crm:*:*:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:3:*:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:3.0:beta:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:3.2:*:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:4:*:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:4:beta:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:4:rc1:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:4.2:*:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:4.2:*:validation:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:4.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:5.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:5.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:5.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:5.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:5.0.4:rc:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:5.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:vtiger:vtiger_crm:5.1.0:rc:*:*:*:*:*:*
More vulnerabilities in Vtiger Vtiger Crm
- CVE-2020-22807 — Critical (CVSS 9.8): An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.
- CVE-2013-3215 — Critical (CVSS 9.8): vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation…
- CVE-2013-3214 — Critical (CVSS 9.8): vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
- CVE-2024-44779 — Critical (CVSS 9.6): A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0…
- CVE-2024-44778 — Critical (CVSS 9.6): A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0…
- CVE-2024-44777 — Critical (CVSS 9.6): A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows…
All CVEs affecting Vtiger Vtiger Crm →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-80155 — Critical (CVSS 10.0): Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of…
- CVE-2026-70200 — Critical (CVSS 10.0): Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an…
- CVE-2026-85706 — Critical (CVSS 10.0): GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and…
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.
- CVE-2026-18051 — Critical (CVSS 10.0): The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache…
- CVE-2026-74764 — Critical (CVSS 10.0): Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a…