CVE-2014-2269: Vtiger CRM

Medium severity, CVSS 6.4. EPSS: 15.7% chance of exploitation in the next 30 days.

modules/Users/ForgotPassword.php in vTiger 6.0 before Security Patch 2 allows remote attackers to reset the password for arbitrary users via a request containing the username, password, and confirmPassword parameters.

Affected products

  • Vtiger Vtiger CRM: version 6.0.0 only

Published 2014-04-22. Last modified 2026-06-17.