First published: Thu Nov 21 2019(Updated: )
In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Vtiger Vtiger Crm | >=7.0<7.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19202 is a vulnerability in Vtiger CRM 7.x before 7.2.0 that allows a user without administrative privileges to change their own role.
CVE-2019-19202 has a severity rating of 8.8 (high).
CVE-2019-19202 allows users without administrative privileges to modify their role in Vtiger CRM.
CVE-2019-19202 is categorized under CWE-276 (Incorrect Default Permissions).
References for CVE-2019-19202 can be found at: http://lists.vtigercrm.com/pipermail/vtigercrm-developers/2019-April/037964.html and https://code.vtiger.com/vtiger/vtigercrm/issues/1126