4
CVSSv2

CVE-2011-0745

Published: 16/03/2011 Updated: 09/10/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

SugarCRM prior to 6.1.3 does not properly handle reloads and direct requests for a warning page produced by a certain duplicate check, which allows remote authenticated users to discover (1) the names of customers via a ShowDuplicates action to the Accounts module, reachable through index.php; or (2) the names of contact persons via a ShowDuplicates action to the Contacts module, reachable through index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

sugarcrm sugarcrm 5.5

sugarcrm sugarcrm 4.1

sugarcrm sugarcrm 1.1b

sugarcrm sugarcrm 1.1c

sugarcrm sugarcrm 2.0.1c

sugarcrm sugarcrm 5.2.0g

sugarcrm sugarcrm 4.5.1i

sugarcrm sugarcrm 3.5.1

sugarcrm sugarcrm 5.2e

sugarcrm sugarcrm 5.0.0

sugarcrm sugarcrm 5.1.0

sugarcrm sugarcrm 6.0.2

sugarcrm sugarcrm 6.0.1

sugarcrm sugarcrm 6.0

sugarcrm sugarcrm 5.2h

sugarcrm sugarcrm 3.5

sugarcrm sugarcrm 1.0

sugarcrm sugarcrm 1.0f

sugarcrm sugarcrm 1.0g

sugarcrm sugarcrm 1.1f

sugarcrm sugarcrm 1.5d

sugarcrm sugarcrm 5.2g

sugarcrm sugarcrm 5.2f

sugarcrm sugarcrm 4.5.0

sugarcrm sugarcrm 5.2d

sugarcrm sugarcrm 5.2c

sugarcrm sugarcrm 5.1.0-beta

sugarcrm sugarcrm

sugarcrm sugarcrm 6.1.1

sugarcrm sugarcrm 5.5.3

sugarcrm sugarcrm 5.5.2

sugarcrm sugarcrm 4.0

sugarcrm sugarcrm 4.5.0f

sugarcrm sugarcrm 5.5.0

sugarcrm sugarcrm 1.1d

sugarcrm sugarcrm 1.1e

sugarcrm sugarcrm 4.5.1

sugarcrm sugarcrm 3.0.1

sugarcrm sugarcrm 4.0.1

sugarcrm sugarcrm 4.2.1

sugarcrm sugarcrm 5.0.0h

sugarcrm sugarcrm 5.5a

sugarcrm sugarcrm 5.5.4

sugarcrm sugarcrm 4.2

sugarcrm sugarcrm 1.1

sugarcrm sugarcrm 1.1a

sugarcrm sugarcrm 2.0.1

sugarcrm sugarcrm 2.0.1a

sugarcrm sugarcrm 4.5.1o

sugarcrm sugarcrm 5.1l

sugarcrm sugarcrm 5.2a

sugarcrm sugarcrm 5.1c

sugarcrm sugarcrm 5.0.0k

sugarcrm sugarcrm 6.1.0

sugarcrm sugarcrm 6.0.3

sugarcrm sugarcrm 5.5.1

Exploits

source: wwwsecurityfocuscom/bid/46885/info SugarCRM is prone to an information-disclosure vulnerability because it fails to restrict access to certain application data Attackers can exploit this issue to obtain sensitive information that may lead to further attacks wwwexampleorg/sugarcrm/indexphp?module=Accounts&action ...
SugarCRM versions 611 and below suffer from a list privilege restriction bypass vulnerability ...