External risk intelligence

Dogfood CRM Spell Script Remote Command Execution

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2009-20010

The vulnerability exists in a CRM application's web-based mail subsystem. CRM systems and their integrated mail or utility scripts are commonly deployed as internet-facing web applications, making this specific endpoint frequently reachable from the public internet.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in the spell-checking component of a CRM's mail system, allowing unauthenticated attackers to execute arbitrary commands on the server. This could potentially lead to a complete system compromise if the affected software is in use.

  • Unauthenticated attackers can run commands on the server.
  • This affects CRM mail systems, a common business tool.
  • Confirm if your CRM mail system is affected and exposed.

Attack Path

How an attacker could exploit the issue

An attacker can reach the vulnerable spell.php script in Dogfood CRM's mail subsystem via a network connection. The script processes user-supplied data from a POST request without proper sanitization, allowing command injection. This could lead to remote command execution on the server.

  • No authentication is required.
  • A POST request to spell.php triggers it.
  • Results in remote command execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary commands on the server. When supported by the advisory, this could impact the integrity and availability of the affected system by enabling the attacker to compromise the server's operating system.

  • Server-side command execution.
  • Via a crafted POST request.
  • Compromise of the underlying server.

Operational Fix

Recommended remediation, mitigation, and detection steps

Action likely falls to the platform or application owner to identify all instances of Dogfood CRM, confirm exposure and business criticality, and then coordinate remediation. The first practical move is to locate all deployments and assess their reachability and impact to prioritize response.

  • Platform or application owners should lead.
  • Verify CRM instances and exposure first.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Dogfood CRM?

Dogfood CRM is a customer relationship management platform used by organizations to track business interactions. Version 2.0.10 includes a mail subsystem designed to help users manage communications, which relies on specific utility scripts—like spell.php—to process text and support integrated messaging features within the application.

What is the vulnerability in CVE-2009-20010?

This flaw is a command injection vulnerability, classified as CWE-78. It occurs when an application passes unsanitized user input directly to a system shell. In this case, the spell.php script fails to clean data received from a network request, allowing the underlying server to mistakenly interpret and run malicious shell commands instead of simply processing text.

How is this command injection triggered?

An attacker triggers the vulnerability by sending a specially crafted POST request containing malicious input to the spell.php script. The bug requires the application to actively process this data through its shell. Simply visiting the page or viewing the mail interface does not initiate the command execution; the server must receive and process the specific, unsanitized payload.

Do I need to worry if my CRM is not internet-facing?

Halo Surface Signal indicates that because this CRM component is typically deployed as a web-accessible utility, it is often reachable from the public internet. If your instance is strictly internal, the risk is lower, but you should still care if any untrusted users on your local network can reach the server, as the vulnerability does not require authentication to execute.

How should I respond to this threat?

Your first step is to perform an inventory of your environment to locate all running instances of Dogfood CRM. Once identified, evaluate whether these instances are accessible over the network. After confirming which systems are reachable, coordinate with your technical team to prioritize remediation of the affected mail subsystem components.

References