include/utils/ListViewUtils.php in vtiger CRM before 5.1.0 allows remote authenticated users to bypass intended access restrictions and read the (1) visibility, (2) location, and (3) recurrence fields of a calendar via a custom view.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2009-09-18T20:00:00Z

Updated: 2024-09-17T02:01:47.464Z

Reserved: 2009-09-18T00:00:00Z

Link: CVE-2009-3251

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2009-09-18T20:30:00.327

Modified: 2017-11-22T16:06:17.213

Link: CVE-2009-3251

cve-icon Redhat

No data.