MEDIUM6.5
GHSA-394m-vxwj-363j
YetiForceCRM Directory Traversal vulnerability
Quick fix
GHSA-394m-vxwj-363j — yetiforce/yetiforce-crm: upgrade to the fixed version with the command below.
composer require yetiforce/yetiforce-crm:^6.5.0Details
Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/yetiforce/yetiforce-crm
Introduced in:
0Fixed in: 6.5.0Fix
composer require yetiforce/yetiforce-crm:^6.5.0References
- https://nvd.nist.gov/vuln/detail/CVE-2023-49508[ADVISORY]
- https://github.com/YetiForceCompany/YetiForceCRM/commit/ba3a348aa6ecdf0a1d8b289cbb679bebcda7a132[WEB]
- https://github.com/YetiForceCompany/YetiForceCRM[PACKAGE]
- https://github.com/c4v4r0n/Research/tree/main/CVE-2023-49508[WEB]
- https://huntr.com/bounties/29ed641d-eb03-4532-aed4-f96e11f78983[WEB]