VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the Migration administrative module to disable arbitrary modules.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Vtiger_crm |
Vtiger |
* |
8.1.0 (including) |
References