An extensive analysis of vtenext CRM version 25.02 revealed multiple critical vulnerabilities that allow unauthorized attackers to bypass authentication mechanisms via three different attack paths, ultimately leading to remote code execution (RCE) on target systems.

The Italian CRM solution, used by many small and medium-sized businesses across the country, now warns of threats.
vtenext: XSS and Session Hijacking
The first attack path exploits a chain of vulnerabilities that combines Reflected Cross-Site Scripting (XSS), CSRF token bypass, and session cookie disclosure. A critical error in `modules/Home/HomeWidgetBlockList.php` where the `widgetId` parameter undergoes insufficient sanitization before reflection in server responses. The vulnerability manifests when JSON responses containing malicious payloads are delivered with Content-Type: text/html headers instead of the safe application/json format. As a result, it allows execution of embedded JavaScript code by the browser.
See also: Tableau Server: Critical vulnerability allows system compromise
Attackers can inject malicious scripts using crafted requests. The exploit becomes particularly dangerous when combined with bypassing CSRF token validation, achieved via HTTP method tampering. The application's dependency on the $_REQUEST superglobal allows attackers to convert POST requests to GET requests, completely bypassing the CSRF protection mechanisms in `include/utils/VteCsrf.php`. This design flaw allows attackers to exploit XSS vulnerabilities without requiring valid CSRF tokens, significantly reducing the complexity of the attack.

SQL Injection Vulnerability
The second attack path, which involves authentication bypass, exploits SQL injection vulnerabilities in `modules/Fax/EditView.php`to extract sensitive user credentials and authentication tokens. The vulnerable code constructs database queries by directly combining user-controlled input data. Although prepared statements are used, the `$fieldname` parameter remains unsanitized, allowing attackers to specify arbitrary database columns to extract.
Additionally, attackers can exploit subquery injection to extract password reset. These extracted tokens allow password reset without user interaction, providing full account hijacking capabilities.
See also: Apple vulnerability: PoC Exploit released for zero-day bug
Instant Password Reset Vulnerability
The most severe vulnerability involves a bug password reset in `hub/rpwd.php`. This access point exposes a change_password action that lacks sufficient security validation, allowing the password to be modified for any user account (using only the target's username). The vulnerable code path in `modules/Users/RecoverPwd.php` processes password change requests without proper user verification. The `skipOldPwdCheck` parameter set to true completely bypasses password verification, allowing attackers to reset any user's credentials via a simple HTTP request. This vulnerability was fixed in version 25.02.1 after the research revealed it.

Remote Code Execution Vulnerability
Once authentication bypass, attackers can escalate the situation and perform remote code execution via various techniques. The application contains multiple Local File Inclusion (LFI) that accept user input in file import operations without proper sanitization. The vulnerabilities are located in: `modules/Settings/LayoutBlockListUtils.php`, `modules/Calendar/ActivityAjax.php` and `modules/Calendar/wdCalendar.php`.
Path traversal sequences (../) allow arbitrary file insertion, with the restriction that target files must have .php extensions. Although upload restrictions prevent direct uploads of PHP files, researchers demonstrated RCE exploitation via pearcmd.php gadgets, when the PEAR framework is present on target systems.
See also: Docker Desktop Windows: Vulnerability leads to system compromise
Additionally, vtenext administrators can upload custom modules via the ModuleManager, providing a direct path to exploitation.
Organizations using vtenext CRM should immediately upgrade to version 25.02.1 or later and implement additional security measures to mitigate these critical vulnerabilities.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The vendor's delayed response to responsible disclosure efforts highlights the importance of proactive security monitoring and rapid deployment of patch updates in enterprise environments.
