CVE-2009-3257 - CERT CVE
ID CVE-2009-3257
Sažetak vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.
Reference
CVSS
Base: 3.6
Impact: 4.9
Exploitability:3.9
Pristup
VektorSloženostAutentikacija
NETWORK HIGH SINGLE
Impact
PovjerljivostCjelovitostDostupnost
NONE PARTIAL PARTIAL
CVSS vektor AV:N/AC:H/Au:S/C:N/I:P/A:P
Zadnje važnije ažuriranje 07-12-2017 - 21:36
Objavljeno 18-09-2009 - 21:30