Directory Listing Vulnerability in Vtiger CRM by Vtiger
CVE-2020-19363

6.5MEDIUM

Key Information:

Vendor

Vtiger

Vendor
CVE Published:
20 January 2021

What is CVE-2020-19363?

The vulnerability in Vtiger CRM v7.2.0 allows attackers to access sensitive information by revealing hidden files and listing directories through the application's /libraries and /layout paths. This could potentially lead to information disclosure, where unauthorized users could exploit this weakness to gain insights into the system's structure and functionality.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-19363 : Directory Listing Vulnerability in Vtiger CRM by Vtiger