SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated users to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php.  NOTE: this issue might be a duplicate of CVE-2011-4559.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2013-10-04T20:00:00Z
Updated: 2024-09-17T01:16:46.042Z
Reserved: 2013-08-08T00:00:00Z
Link: CVE-2013-5091
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Deferred
Published: 2013-10-04T20:55:03.857
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-5091
 Redhat
                        Redhat
                    No data.