Описание
vtiger CRM before 5.3.0 does not properly recognize the disabled status of a field in the Leads module, which allows remote authenticated users to bypass intended access restrictions by reading a previously created report.
Ссылки
- ExploitVendor Advisory
- ExploitVendor Advisory
- Vendor Advisory
- ExploitVendor Advisory
- ExploitVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.3.0 (исключая)
cpe:2.3:a:vtiger:vtiger_crm:*:*:*:*:*:*:*:*
EPSS
Процентиль: 37%
0.0016
Низкий
4 Medium
CVSS2
Дефекты
CWE-264
Связанные уязвимости
github
больше 3 лет назад
vtiger CRM before 5.3.0 does not properly recognize the disabled status of a field in the Leads module, which allows remote authenticated users to bypass intended access restrictions by reading a previously created report.
EPSS
Процентиль: 37%
0.0016
Низкий
4 Medium
CVSS2
Дефекты
CWE-264