CVE-2019-19202: Vtiger CRM

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request.

Affected products

  • Vtiger Vtiger CRM: from 7.0, before 7.2.0 (fixed in 7.2.0)

Published 2019-11-21. Last modified 2026-06-17.