Topline Opportunity Form (aka XLS Opp form) before 2015-02-15 does not properly restrict access to database-connection strings, which allows attackers to read the cleartext version of sensitive credential and e-mail address information via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/669156 | third party advisory us government resource |
http://www.kb.cert.org/vuls/id/BLUU-9RUTH4 | third party advisory us government resource |
http://www.securityfocus.com/bid/72518 | vdb entry |