VulnerabilityModified
CVE-2009-3257
vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.
LOW 3.6EPSS 0.86%
Does this matter?
Lower severity and a low EPSS score (0.86%). Track it; it rarely justifies an emergency change on its own.
Description
vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.
- CVSS 2.0
- 3.6 LOWAV:N/AC:H/Au:S/C:N/I:P/A:P
- EPSS
- 0.86% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- vtiger/vtiger crm
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/36309Third Party Advisory
- http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/5055Exploit, Vendor Advisory
- http://secunia.com/advisories/36309Third Party Advisory
- http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/5055Exploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.