CVE-2007-3600
Estado: ModificadaMedia (4)—
WordPlugin in the wordintegration component in vtiger CRM before 5.0.3 allows remote authenticated users to bypass field level security permissions and merge arbitrary fields in an Email template, as demonstrated by the fields in the Contact module.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N
- Puntuación base: 4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.78%
- Percentil entre todas las CVEs puntuadas: 77
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://osvdb.org/45784
- http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/10845
- http://trac.vtiger.com/cgi-bin/trac.cgi/report/9
- http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/3790
- http://osvdb.org/45784
- http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/10845
- http://trac.vtiger.com/cgi-bin/trac.cgi/report/9
- http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/3790
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-3600",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-07-06T19:30:00.000",
"references": [
{
"url": "http://osvdb.org/45784",
"source": "cve@mitre.org"
},
{
"url": "http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/10845",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://trac.vtiger.com/cgi-bin/trac.cgi/report/9",
"source": "cve@mitre.org"
},
{
"url": "http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/3790",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/45784",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/10845",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://trac.vtiger.com/cgi-bin/trac.cgi/report/9",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/3790",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "WordPlugin in the wordintegration component in vtiger CRM before 5.0.3 allows remote authenticated users to bypass field level security permissions and merge arbitrary fields in an Email template, as demonstrated by the fields in the Contact module."
},
{
"lang": "es",
"value": "WordPlugin en el componente wordintegration de vtiger CRM versiones anteriores a 5.0.3 permite a usuarios remotos autenticados evitar permisos de seguridad a nivel de campo y mezclar ficheros de su elección en una plantilla de correo electrónico, como se demuestra con los campos del módulo Contact."
}
],
"lastModified": "2026-06-16T22:42:21.443",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vtiger:vtiger_crm:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9E8668A7-60BA-45AA-A159-26890ADB6A0A",
"versionEndIncluding": "5.0.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}