vtiger CRM before 5.3.0 does not properly recognize the disabled status of a field in the Leads module, which allows remote authenticated users to bypass intended access restrictions by reading a previously created report.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vtiger_crm | Vtiger | * | 5.3.0 (excluding) |