VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the Migration administrative module to disable arbitrary modules.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Vtiger_crm | Vtiger | * | 8.1.0 (including) |
References