CVE-2019-19202: Vtiger CRM
High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.
In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request.
Affected products
- Vtiger Vtiger CRM: from 7.0, before 7.2.0 (fixed in 7.2.0)
Published 2019-11-21. Last modified 2026-06-17.