VDB
Sign up
MEDIUM6.5

GHSA-394m-vxwj-363j

YetiForceCRM Directory Traversal vulnerability

Quick fix

GHSA-394m-vxwj-363j — yetiforce/yetiforce-crm: upgrade to the fixed version with the command below.

composer require yetiforce/yetiforce-crm:^6.5.0

Details

Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/yetiforce/yetiforce-crm
Introduced in: 0Fixed in: 6.5.0
Fixcomposer require yetiforce/yetiforce-crm:^6.5.0

References