index.php in vtiger CRM before 5.0.3 allows remote authenticated users to perform administrative changes to arbitrary profile settings via a certain profilePrivileges action in the Users module.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Vtiger_crm |
Vtiger |
* |
5.0.2 (including) |
References