WordPlugin in the wordintegration component in vtiger CRM before 5.0.3 allows remote authenticated users to bypass field level security permissions and merge arbitrary fields in an Email template, as demonstrated by the fields in the Contact module.
References
Configurations
History
21 Nov 2024, 00:33
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/45784 - | |
References | () http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/10845 - Patch | |
References | () http://trac.vtiger.com/cgi-bin/trac.cgi/report/9 - | |
References | () http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/3790 - |
Information
Published : 2007-07-06 19:30
Updated : 2024-11-21 00:33
NVD link : CVE-2007-3600
Mitre link : CVE-2007-3600
CVE.ORG link : CVE-2007-3600
JSON object : View
Products Affected
vtiger
- vtiger_crm
CWE