CVE-2025-1618

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Feb 24, 2025
Updated: Mar 3, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2025-1618 is a newly disclosed vulnerability that impacts the vTiger CRM 6.4.0 and 6.5.0 versions. The issue lies within the unknown code of the /modules/Mobile/index.php file and is classified as a cross-site scripting (XSS) vulnerability. An attacker can exploit this flaw by manipulating the _operation argument, which allows them to inject malicious scripts remotely. The exploit is currently public, increasing the risk of attacks. To mitigate this vulnerability, users are advised to upgrade to vTiger CRM 7.0 as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share