VulnerabilityModified
CVE-2008-3458
Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail merge templates via a direct request to the wordtemplatedownload directory.
MEDIUM 5.0EPSS 2.80%
Does this matter?
Lower severity and a low EPSS score (2.80%). Track it; it rarely justifies an emergency change on its own.
Description
Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail merge templates via a direct request to the wordtemplatedownload directory.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.80% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- vtiger/vtiger crm
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/28370Third Party Advisory
- http://sourceforge.net/project/shownotes.php?release_id=567189Broken Link
- http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/11811Exploit, Vendor Advisory
- http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/2107Vendor Advisory
- http://wiki.vtiger.com/index.php/Vtiger_CRM_5.0.4_-_Release_NotesVendor Advisory
- http://www.osvdb.org/40218Broken Link
- http://www.securityfocus.com/bid/27228Patch, Third Party Advisory, VDB Entry
- http://secunia.com/advisories/28370Third Party Advisory
- http://sourceforge.net/project/shownotes.php?release_id=567189Broken Link
- http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/11811Exploit, Vendor Advisory
- http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/2107Vendor Advisory
- http://wiki.vtiger.com/index.php/Vtiger_CRM_5.0.4_-_Release_NotesVendor Advisory
- http://www.osvdb.org/40218Broken Link
- http://www.securityfocus.com/bid/27228Patch, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.