VulnerabilityModified
CVE-2007-3604
vtiger CRM before 5.0.3 allows remote authenticated users with access to the Analytics DashBoard menu to bypass data restrictions and read the pipeline of the entire organization, possibly involving modules/Potentials/Potentials.php.
MEDIUM 4.0EPSS 1.08%
Does this matter?
Lower severity and a low EPSS score (1.08%). Track it; it rarely justifies an emergency change on its own.
Description
vtiger CRM before 5.0.3 allows remote authenticated users with access to the Analytics DashBoard menu to bypass data restrictions and read the pipeline of the entire organization, possibly involving modules/Potentials/Potentials.php.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.08% probability · 63th percentile
- CISA KEV
- Not listed
- Affected
- vtiger/vtiger crm
- Source
- cve@mitre.org
References
- http://forums.vtiger.com/viewtopic.php?p=44717
- http://osvdb.org/45783
- http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/10423Patch
- http://trac.vtiger.com/cgi-bin/trac.cgi/report/9
- http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/3196
- http://forums.vtiger.com/viewtopic.php?p=44717
- http://osvdb.org/45783
- http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/10423Patch
- http://trac.vtiger.com/cgi-bin/trac.cgi/report/9
- http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/3196
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.