Description
Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component.
Remediation
References
Related Vulnerabilities
phpMyAdmin 7PK - Security Features Vulnerability (CVE-2016-1927)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2082)
WordPress Plugin Archivist-Custom Archive Templates Multiple Vulnerabilities (1.7.4)
WebLogic Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2022-22965)