{"id":"CVE-2023-49508","aliases":["GHSA-394m-vxwj-363j"],"url":"https://o3.security/vulnerability/CVE-2023-49508","summary":"YetiForceCRM Directory Traversal vulnerability","details":"Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component.","published":"2024-02-16T00:00:00Z","modified":"2026-07-15T01:49:20.389909925Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"yetiforce/yetiforce-crm","fixedVersion":"6.5.0"}],"fix":{"url":"https://github.com/YetiForceCompany/YetiForceCRM/commit/ba3a348aa6ecdf0a1d8b289cbb679bebcda7a132","label":"YetiForceCompany/YetiForceCRM@ba3a348"},"references":[{"type":"WEB","url":"https://github.com/c4v4r0n/Research/tree/main/CVE-2023-49508"},{"type":"WEB","url":"https://huntr.com/bounties/29ed641d-eb03-4532-aed4-f96e11f78983/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49508.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-49508"},{"type":"FIX","url":"https://github.com/YetiForceCompany/YetiForceCRM/commit/ba3a348aa6ecdf0a1d8b289cbb679bebcda7a132"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:20.389909925Z"}}