Topline Opportunity Form (aka XLS Opp form) before 2015-02-15 does not properly restrict access to database-connection strings, which allows attackers to read the cleartext version of sensitive credential and e-mail address information via unspecified vectors.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1608
Reference (s):
- BID:72518
- URL: http://www.securityfocus.com/bid/72518
- CERT-VN:VU#669156
- URL: http://www.kb.cert.org/vuls/id/669156
- http://www.kb.cert.org/vuls/id/BLUU-9RUTH4