CVE-2009-3257
18.09.2009, 21:30
vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.Enginsight
Vendor | Product | Version |
---|---|---|
vtiger | vtiger_crm | 𝑥 < 5.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration