PT-2007-4857 · Mozilla+1 · Thunderbird+1

Jinxed

·

Publicado

2007-07-06

·

Atualizado

2008-09-05

·

CVE-2007-3602

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions vtiger CRM versions prior to 5.0.3
Description The issue concerns the SOAP webservice in vtiger CRM, where it fails to verify if an authenticated account is active. This allows remote authenticated users with inactive accounts to access and modify data. An example of this exploit is demonstrated through the Thunderbird plugin.
Recommendations For versions prior to 5.0.3, update to version 5.0.3 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-3602

Produtos afetados

Thunderbird
Vtiger Crm