CVE-2023-49508

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 16, 2024
Updated: Jan 6, 2025
CWE ID 22

Summary

CVE-2023-49508 is a Directory Traversal vulnerability affecting YetiForceCompany's YetiForceCRM versions 6.4.0 and prior. This issue grants remote, authenticated attackers access to sensitive information by manipulating the license parameter in the LibraryLicense.php module. The vulnerability can be exploited to traverse and access unintended directories, potentially uncovering confidential data. YetiForce is advised to update to a patched version promptly to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Yetiforce Customer Relationship Management