CVE-2023-49508
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Feb 16, 2024
Updated: Jan 6, 2025
CWE ID 22
Summary
CVE-2023-49508 is a Directory Traversal vulnerability affecting YetiForceCompany's YetiForceCRM versions 6.4.0 and prior. This issue grants remote, authenticated attackers access to sensitive information by manipulating the license parameter in the LibraryLicense.php module. The vulnerability can be exploited to traverse and access unintended directories, potentially uncovering confidential data. YetiForce is advised to update to a patched version promptly to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Yetiforce Customer Relationship Management