CVE

Id
40692  
CVE No.
CVE-2009-3257  
Status
Candidate  
Description
vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.  
Phase
Assigned (20090918)  
Votes
None (candidate not yet proposed)  
Comments