SB2016080110 - Modification of user accounts in Vtiger CRM
Published: August 1, 2016 Updated: August 2, 2016
Security Bulletin ID
SB2016080110
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Modification of user accounts (CVE-ID: CVE-2016-4834)
The vulnerability allows a remote attacker to modify user data on the target system.The vulnerability exists due to a flaw in 'modules/Users/actions/Save.php' in the Users_Save_Action class. A remote authenticated attacker can create or modify user accounts via unspecified vectors.
Successful exploitation of this vulnerability may result in modification of system information.
Remediation
Install update from vendor's website.