modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticated users to create or modify user accounts via unspecified vectors.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: jpcert
Published: 2016-08-01T01:00:00
Updated: 2024-08-06T00:39:26.311Z
Reserved: 2016-05-17T00:00:00
Link: CVE-2016-4834

No data.

Status : Modified
Published: 2016-08-01T02:59:14.620
Modified: 2024-11-21T02:53:04.590
Link: CVE-2016-4834

No data.