CVE-2016-4834

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
01/08/2016
Last modified:
12/04/2025

Description

modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticated users to create or modify user accounts via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vtiger:vtiger_crm:*:*:*:*:*:*:*:* 6.4.0 (including)