WordPlugin in the wordintegration component in vtiger CRM before 5.0.3 allows remote authenticated users to bypass field level security permissions and merge arbitrary fields in an Email template, as demonstrated by the fields in the Contact module.
References
Configurations
Information
Published : 2007-07-06 12:30
Updated : 2008-11-14 22:53
NVD link : CVE-2007-3600
Mitre link : CVE-2007-3600
JSON object : View
CWE
Products Affected
vtiger
- vtiger_crm