vtiger CRM 4.2.4, and possibly earlier, allows remote attackers to bypass authentication and access administrative modules via a direct request to index.php with a modified module parameter, as demonstrated using the Settings module.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vtiger_crm | Vtiger | 4.2 (including) | 4.2 (including) |
Vtiger_crm | Vtiger | 4.2.4 (including) | 4.2.4 (including) |