Topline Opportunity Form (aka XLS Opp form) before 2015-02-15 does not properly restrict access to database-connection strings, which allows attackers to read the cleartext version of sensitive credential and e-mail address information via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Opportunity_form | Topline_systems | - (including) | - (including) |