CVE-2011-4679
07.12.2011, 19:55
vtiger CRM before 5.3.0 does not properly recognize the disabled status of a field in the Leads module, which allows remote authenticated users to bypass intended access restrictions by reading a previously created report.Enginsight
Vendor | Product | Version |
---|---|---|
vtiger | vtiger_crm | 𝑥 < 5.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References