CVE-2007-3604
Estado: ModificadaMedia (4)—
vtiger CRM before 5.0.3 allows remote authenticated users with access to the Analytics DashBoard menu to bypass data restrictions and read the pipeline of the entire organization, possibly involving modules/Potentials/Potentials.php.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N
- Puntuación base: 4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.08%
- Percentil entre todas las CVEs puntuadas: 64
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://forums.vtiger.com/viewtopic.php?p=44717
- http://osvdb.org/45783
- http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/10423
- http://trac.vtiger.com/cgi-bin/trac.cgi/report/9
- http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/3196
- http://forums.vtiger.com/viewtopic.php?p=44717
- http://osvdb.org/45783
- http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/10423
- http://trac.vtiger.com/cgi-bin/trac.cgi/report/9
- http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/3196
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-3604",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-07-06T19:30:00.000",
"references": [
{
"url": "http://forums.vtiger.com/viewtopic.php?p=44717",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/45783",
"source": "cve@mitre.org"
},
{
"url": "http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/10423",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://trac.vtiger.com/cgi-bin/trac.cgi/report/9",
"source": "cve@mitre.org"
},
{
"url": "http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/3196",
"source": "cve@mitre.org"
},
{
"url": "http://forums.vtiger.com/viewtopic.php?p=44717",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/45783",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/10423",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://trac.vtiger.com/cgi-bin/trac.cgi/report/9",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/3196",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "vtiger CRM before 5.0.3 allows remote authenticated users with access to the Analytics DashBoard menu to bypass data restrictions and read the pipeline of the entire organization, possibly involving modules/Potentials/Potentials.php."
},
{
"lang": "es",
"value": "vtiger CRM versiones anteriores a 5.0.3 permite a usuarios remotos autenticados con acceso al menú Analytics DashBoard evitar restricciones de datos y leer la lista de acciones próximas de la organización entera, posiblemente involucrando modules/Potentials/Potentials.php."
}
],
"lastModified": "2026-06-16T22:42:21.880",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vtiger:vtiger_crm:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9E8668A7-60BA-45AA-A159-26890ADB6A0A",
"versionEndIncluding": "5.0.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}