dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this module via a crafted URL. NOTE: some of these details are obtained from third party information.
| Software | From | Fixed in |
|---|---|---|
| dotproject / dotproject | - | 2.0.4.x |