Описание
YetiForceCRM Directory Traversal vulnerability
Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component.
Пакеты
Наименование
yetiforce/yetiforce-crm
composer
Затронутые версииВерсия исправления
< 6.5.0
6.5.0
Связанные уязвимости
CVSS3: 6.5
nvd
почти 2 года назад
Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component.