User Account Management Flaw in Vtiger CRM by Vtiger
CVE-2016-4834

8.1HIGH

Key Information:

Vendor

Vtiger

Vendor
CVE Published:
1 August 2016

What is CVE-2016-4834?

A vulnerability exists in the Vtiger CRM where the modules/Users/actions/Save.php file fails to adequately restrict user-save actions. This oversight enables remote authenticated users to exploit the system, allowing them to create or modify user accounts through unspecified vectors. The lack of proper access controls poses significant risks to the integrity and security of user data.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2016-4834 : User Account Management Flaw in Vtiger CRM by Vtiger