Back to Database
Status published
Low
CVE-2007-3601
vtiger CRM before 5.0.3, when a migrated build is used,...
Vulnerability Description
vtiger CRM before 5.0.3, when a migrated build is used, allows remote authenticated users to read certain other users' calendar activities via a (1) home page or (2) event list view.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-3601
Credits & Attribution
No credits recorded in the NVD database.
References
More from vtiger
View All →CVE-2022-38335
Vtiger CRM v7.4.0 was discovered to contain a stored cross-site...
Unknown
0
CVE-2020-22807
An issue was dicovered in vtiger crm 7.2. Union sql...
Critical
9.8
CVE-2020-19363
Vtiger CRM v7.2.0 allows an attacker to display hidden files,...
Medium
6.5
CVE-2020-19362
Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the...
Medium
6.1
CVE-2019-5009
Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the...
High
7.2
Affected Vendor
vtiger
View all reports →Affected Software
vtiger crm
Vulnerable Versions:
0
Timeline
Official Publish:
July 6th, 2007
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.