Unrated severityNVD Advisory· Published Sep 18, 2009· Updated Apr 23, 2026
CVE-2009-3257
CVE-2009-3257
Description
vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- trac.vtiger.com/cgi-bin/trac.cgi/ticket/5055nvdExploitVendor Advisory
- secunia.com/advisories/36309nvdThird Party Advisory
News mentions
0No linked articles in our index yet.