MEDIUM · 4.0

CVE-2007-3600

WordPlugin in the wordintegration component in vtiger CRM before 5.0.3 allows remote authenticated users to bypass field level security permissions and merge arbitrary fields in an Email template, as ...

Vulnerability Description

WordPlugin in the wordintegration component in vtiger CRM before 5.0.3 allows remote authenticated users to bypass field level security permissions and merge arbitrary fields in an Email template, as demonstrated by the fields in the Contact module.

CVSS Score

4.0

MEDIUM

AV:N/AC:L/Au:S/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
VtigerVtiger Crm<= 5.0.2

References

FAQ

What is CVE-2007-3600?

CVE-2007-3600 is a vulnerability with a CVSS score of 4.0 (MEDIUM). WordPlugin in the wordintegration component in vtiger CRM before 5.0.3 allows remote authenticated users to bypass field level security permissions and merge arbitrary fields in an Email template, as ...

How severe is CVE-2007-3600?

CVE-2007-3600 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-3600?

Check the references section above for vendor advisories and patch information. Affected products include: Vtiger Vtiger Crm.