Описание
vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.
Ссылки
- Third Party Advisory
- ExploitVendor Advisory
- Third Party Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.1.0 (исключая)
cpe:2.3:a:vtiger:vtiger_crm:*:*:*:*:*:*:*:*
EPSS
Процентиль: 35%
0.00142
Низкий
3.6 Low
CVSS2
Дефекты
CWE-264
Связанные уязвимости
github
почти 4 года назад
vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.
EPSS
Процентиль: 35%
0.00142
Низкий
3.6 Low
CVSS2
Дефекты
CWE-264