CVE-2008-3458
04.08.2008, 19:41
Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail merge templates via a direct request to the wordtemplatedownload directory.Enginsight
Vendor | Product | Version |
---|---|---|
vtiger | vtiger_crm | 𝑥 ≤ 5.0.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References