CVE

Id
52591  
CVE No.
CVE-2011-4679  
Status
Candidate  
Description
vtiger CRM before 5.3.0 does not properly recognize the disabled status of a field in the Leads module, which allows remote authenticated users to bypass intended access restrictions by reading a previously created report.  
Phase
Assigned (20111206)  
Votes
None (candidate not yet proposed)  
Comments