4
CVE-2007-3604
- EPSS 1.08%
- Veröffentlicht 06.07.2007 19:30:00
- Zuletzt bearbeitet 16.06.2026 22:42:21
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
vtiger CRM before 5.0.3 allows remote authenticated users with access to the Analytics DashBoard menu to bypass data restrictions and read the pipeline of the entire organization, possibly involving modules/Potentials/Potentials.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Vtiger ≫ Vtiger Crm Version <= 5.0.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.08% | 0.606 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
http://trac.vtiger.com/cgi-bin/trac.cgi/report/9
http://forums.vtiger.com/viewtopic.php?p=44717
http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/10423
http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/3196
http://osvdb.org/45783