Security Advisory

CVE-2019-14767

7.5
HIGH

Vulnerability Description

In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an unauthenticated user to download arbitrary files from the server.
Published Date January 21, 2020
Official Source NIST NVD Advisory