Security Advisory

CVE-2008-3458

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2008-08-04 19:00:00
Last updated 2024-09-16 16:18:19
Assigner mitre
State PUBLISHED

Description

Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail merge templates via a direct request to the wordtemplatedownload directory.