CyberRota Analysis
AI analysis pending.
CVE
CVE-2008-3458
Severity
MEDIUM
CVSS
5
EPSS
2.80%
Original NVD Description
Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail merge templates via a direct request to the wordtemplatedownload directory.