Access Control Flaw in CiviCRM Software by CiviCRM
CVE-2013-4661
Currently unrated
What is CVE-2013-4661?
The vulnerability in CiviCRM allows remote authenticated users with the 'access CiviCRM' permission to bypass critical role-based access control restrictions. This flaw permits unauthorized access to sensitive data, like custom contribution information, without possessing the requisite permissions, thereby compromising data security and potentially leading to unauthorized data exposure.
