Total vulnerabilities in the database
vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.
Software | From | Fixed in |
---|---|---|
vtiger / vtiger_crm | - | 5.1.0 |