Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Samuel De Grace

#15336of 53,639
17.6Total CVSS
Vulnerabilities · 2
High
2
PT-2019-15781
8.8
2019-11-21
Vtiger · Vtiger · CVE-2019-19202
**Name of the Vulnerable Software and Affected Versions** Vtiger versions prior to 7.2.0 **Description** The issue concerns the My Preferences saving functionality, which allows a user without administrative privileges to change their own role. This can be achieved by adding `roleid=H2` to a POST request. **Recommendations** For versions prior to 7.2.0, update to version 7.2.0 or later to resolve the issue.
PT-2019-12155
8.8
2019-05-17
Vtiger · Vtiger Crm · CVE-2019-11057
**Name of the Vulnerable Software and Affected Versions** Vtiger CRM versions prior to 7.1.0 hotfix3 **Description** The issue allows authenticated users to execute arbitrary SQL commands due to a SQL injection vulnerability. **Recommendations** For versions prior to 7.1.0 hotfix3, update to version 7.1.0 hotfix3 or later to resolve the issue.