Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-6222

Опубликовано: 04 дек. 2007
Источник: nvd
CVSS2: 6.5
EPSS Низкий

Описание

The CheckCustomerAccess function in functions.php in CRM-CTT Interleave before 4.2.0 (formerly CRM-CTT) does not properly verify user privileges, which allows remote authenticated users with the LIMITTOCUSTOMERS privilege to bypass intended access restrictions and edit non-active user settings. NOTE: some of these details are obtained from third party information.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:crm_ctt:interleave:*:*:*:*:*:*:*:*
Версия до 4.2.0 (включая)

EPSS

Процентиль: 47%
0.00244
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
почти 4 года назад

The CheckCustomerAccess function in functions.php in CRM-CTT Interleave before 4.2.0 (formerly CRM-CTT) does not properly verify user privileges, which allows remote authenticated users with the LIMITTOCUSTOMERS privilege to bypass intended access restrictions and edit non-active user settings. NOTE: some of these details are obtained from third party information.

EPSS

Процентиль: 47%
0.00244
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-264