CVE

Id
65038  
CVE No.
CVE-2013-5091  
Status
Candidate  
Description
SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated users to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php. NOTE: this issue might be a duplicate of CVE-2011-4559.  
Phase
Assigned (20130808)  
Votes
None (candidate not yet proposed)  
Comments