CVE-2016-4834: Vtiger CRM

High severity, CVSS 8.1. EPSS: 2.2% chance of exploitation in the next 30 days.

modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticated users to create or modify user accounts via unspecified vectors.

Affected products

  • Vtiger Vtiger CRM: up to and including 6.4.0

Published 2016-08-01. Last modified 2026-06-17.