Required CVE Record Information
Description
The report module in vtiger CRM before 5.0.3 does not properly apply security rules, which allows remote authenticated users to read arbitrary private module entries.
References 3 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- http://trac.vtiger.com/cgi-bin/trac.cgi/report/9 x_transferred
- osvdb.org: 45804 vdb-entryx_transferred
- http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/2692 x_transferred