MEDIUM
The CheckCustomerAccess function in functions.php in CRM-CTT Interleave before 4.2.0 (formerly CRM-CTT) does not properly verify user privileges, which allows remote authenticated users with the LIMITTOCUSTOMERS privilege to bypass intended access restrictions and edit non-active user settings
Published Dec 4, 2007
6.5
MEDIUMCVSS 2.0
EPSS 1.10%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.