Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vtiger vtiger crm 5.0.3 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2007-3617
The report module in vtiger CRM prior to 5.0.3 does not properly apply security rules, which allows remote authenticated users to read arbitrary private module entries.
Vtiger Vtiger Crm
NA
CVE-2007-3599
vtiger CRM prior to 5.0.3 allows remote authenticated users to import and export the information for a contact even when they only have the View permission.
Vtiger Vtiger Crm
NA
CVE-2007-3616
index.php in vtiger CRM prior to 5.0.3 allows remote authenticated users to perform administrative changes to arbitrary profile settings via a certain profilePrivileges action in the Users module.
Vtiger Vtiger Crm
NA
CVE-2007-3601
vtiger CRM prior to 5.0.3, when a migrated build is used, allows remote authenticated users to read certain other users' calendar activities via a (1) home page or (2) event list view.
Vtiger Vtiger Crm
NA
CVE-2007-3604
vtiger CRM prior to 5.0.3 allows remote authenticated users with access to the Analytics DashBoard menu to bypass data restrictions and read the pipeline of the entire organization, possibly involving modules/Potentials/Potentials.php.
Vtiger Vtiger Crm
NA
CVE-2007-3603
SQL injection vulnerability in the dashboard (include/utils/SearchUtils.php) in vtiger CRM prior to 5.0.3 allows remote authenticated users to execute arbitrary SQL commands via the assigned_user_id parameter in a Potentials ListView action to index.php.
Vtiger Vtiger Crm
NA
CVE-2007-3602
The SOAP webservice in vtiger CRM prior to 5.0.3 does not ensure that authenticated accounts are active, which allows remote authenticated users with inactive accounts to access and modify data, as demonstrated by the Thunderbird plugin.
Vtiger Vtiger Crm
NA
CVE-2007-3600
WordPlugin in the wordintegration component in vtiger CRM prior to 5.0.3 allows remote authenticated users to bypass field level security permissions and merge arbitrary fields in an Email template, as demonstrated by the fields in the Contact module.
Vtiger Vtiger Crm
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
brute force
CVE-2024-24908
open redirect
CVE-2024-31497
CVE-2023-45866
CVE-2024-4135
CVE-2024-25523
cache poisoning
CVE-2024-4649
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2