{"api_version":"1","generated_at":"2026-07-23T09:37:37+00:00","cve":"CVE-2007-3600","urls":{"html":"https://cve.report/CVE-2007-3600","api":"https://cve.report/api/cve/CVE-2007-3600.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-3600","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-3600"},"summary":{"title":"CVE-2007-3600","description":"WordPlugin in the wordintegration component in vtiger CRM before 5.0.3 allows remote authenticated users to bypass field level security permissions and merge arbitrary fields in an Email template, as demonstrated by the fields in the Contact module.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-07-06 19:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:L/Au:S/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://osvdb.org/45784","name":"http://osvdb.org/45784","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/3790","name":"http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/3790","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"#3790 (WordPlugin : Field level security not working) - vtiger development - Trac","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://trac.vtiger.com/cgi-bin/trac.cgi/report/9","name":"http://trac.vtiger.com/cgi-bin/trac.cgi/report/9","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"{9} Tickets Closed in 5.0.3 - vtiger development - Trac","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/10845","name":"http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/10845","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Changeset 10845 - vtiger development - Trac","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-3600","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-3600","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"3600","vulnerable":"1","versionEndIncluding":"5.0.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vtiger","cpe5":"vtiger_crm","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:21:36.464Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/3790"},{"name":"45784","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/45784"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://trac.vtiger.com/cgi-bin/trac.cgi/report/9"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/10845"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-05-31T00:00:00.000Z","descriptions":[{"lang":"en","value":"WordPlugin in the wordintegration component in vtiger CRM before 5.0.3 allows remote authenticated users to bypass field level security permissions and merge arbitrary fields in an Email template, as demonstrated by the fields in the Contact module."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2008-11-15T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/3790"},{"name":"45784","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/45784"},{"tags":["x_refsource_CONFIRM"],"url":"http://trac.vtiger.com/cgi-bin/trac.cgi/report/9"},{"tags":["x_refsource_MISC"],"url":"http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/10845"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-3600","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"WordPlugin in the wordintegration component in vtiger CRM before 5.0.3 allows remote authenticated users to bypass field level security permissions and merge arbitrary fields in an Email template, as demonstrated by the fields in the Contact module."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/3790","refsource":"CONFIRM","url":"http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/3790"},{"name":"45784","refsource":"OSVDB","url":"http://osvdb.org/45784"},{"name":"http://trac.vtiger.com/cgi-bin/trac.cgi/report/9","refsource":"CONFIRM","url":"http://trac.vtiger.com/cgi-bin/trac.cgi/report/9"},{"name":"http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/10845","refsource":"MISC","url":"http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/10845"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-3600","datePublished":"2007-07-06T19:00:00.000Z","dateReserved":"2007-07-06T00:00:00.000Z","dateUpdated":"2024-08-07T14:21:36.464Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-07-06 19:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:vtiger:vtiger_crm:*:*:*:*:*:*:*:*","versionEndIncluding":"5.0.2","matchCriteriaId":"9E8668A7-60BA-45AA-A159-26890ADB6A0A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"3600","Ordinal":"1","Title":"CVE-2007-3600","CVE":"CVE-2007-3600","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"3600","Ordinal":"1","NoteData":"WordPlugin in the wordintegration component in vtiger CRM before 5.0.3 allows remote authenticated users to bypass field level security permissions and merge arbitrary fields in an Email template, as demonstrated by the fields in the Contact module.","Type":"Description","Title":"CVE-2007-3600"},{"CveYear":"2007","CveId":"3600","Ordinal":"2","NoteData":"2007-07-06","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"3600","Ordinal":"3","NoteData":"2008-11-15","Type":"Other","Title":"Modified"}]}}}