Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| yetiforce/yetiforce-crm(Packagist) | 0 | 6.5.0 | N/A |
CVSS Metrics