The report module in vtiger CRM before 5.0.3 does not properly apply security rules, which allows remote authenticated users to read arbitrary private module entries.
References
Configurations
History
21 Nov 2024, 00:33
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/45804 - | |
References | () http://trac.vtiger.com/cgi-bin/trac.cgi/report/9 - Patch | |
References | () http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/2692 - |
Information
Published : 2007-07-06 19:30
Updated : 2024-11-21 00:33
NVD link : CVE-2007-3617
Mitre link : CVE-2007-3617
CVE.ORG link : CVE-2007-3617
JSON object : View
Products Affected
vtiger
- vtiger_crm
CWE