CVE Vulnerabilities

CVE-2011-4679

Published: Dec 07, 2011 | Modified: Nov 22, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

vtiger CRM before 5.3.0 does not properly recognize the disabled status of a field in the Leads module, which allows remote authenticated users to bypass intended access restrictions by reading a previously created report.

Affected Software

Name Vendor Start Version End Version
Vtiger_crm Vtiger * 5.3.0 (excluding)

References