3.6
CVSSv2

CVE-2009-3257

Published: 18/09/2009 Updated: 07/12/2017
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:N/AC:H/Au:S/C:N/I:P/A:P

Vulnerability Summary

vtiger CRM prior to 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.

Vulnerable Product Search on Vulmon Subscribe to Product

vtiger vtiger crm