SQL injection vulnerability in the dashboard (include/utils/SearchUtils.php) in vtiger CRM before 5.0.3 allows remote authenticated users to execute arbitrary SQL commands via the assigned_user_id parameter in a Potentials ListView action to index.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vtiger_crm | Vtiger | * | 5.0.2 (including) |