Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.