CVE-2009-3257
3.6
Vector
AV:N/AC:H/Au:S/C:N/I:P/A:P
Exploitability: 3.9 / Impact: 4.9
Source: NVD
Description
vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.
Affected (1)
Products: Vtiger: Vtiger Crm
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.1.0 |
Related CWEs
References (4)
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Timeline
No history available yet.