CVE Vulnerabilities

CVE-2009-3257

Published: Sep 18, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:N/AC:H/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.

Affected Software

NameVendorStart VersionEnd Version
Vtiger_crmVtiger*5.1.0 (excluding)

References