Security Advisory

CVE-2011-4679

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2011-12-07 19:00:00
Last updated 2024-09-16 23:45:30
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

vtiger CRM before 5.3.0 does not properly recognize the disabled status of a field in the Leads module, which allows remote authenticated users to bypass intended access restrictions by reading a previously created report.