Vtiger

Vtiger Crm

76 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.73%
  • Veröffentlicht 29.08.2024 18:15:14
  • Zuletzt bearbeitet 05.07.2026 01:20:28

A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

  • EPSS 0.72%
  • Veröffentlicht 29.08.2024 18:15:14
  • Zuletzt bearbeitet 05.07.2026 01:20:27

A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

  • EPSS 0.32%
  • Veröffentlicht 29.08.2024 18:15:14
  • Zuletzt bearbeitet 05.07.2026 01:20:26

An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.

Exploit
  • EPSS 0.4%
  • Veröffentlicht 16.08.2024 17:15:15
  • Zuletzt bearbeitet 28.04.2025 14:09:10

VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module to disable arbitrary modules.

Exploit
  • EPSS 0.49%
  • Veröffentlicht 16.08.2024 17:15:15
  • Zuletzt bearbeitet 28.04.2025 14:10:13

VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module.

Exploit
  • EPSS 1.66%
  • Veröffentlicht 30.04.2024 13:15:46
  • Zuletzt bearbeitet 22.04.2025 17:53:58

modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).

  • EPSS 0.95%
  • Veröffentlicht 14.09.2023 23:15:07
  • Zuletzt bearbeitet 21.11.2024 08:14:23

SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.

Exploit
  • EPSS 0.72%
  • Veröffentlicht 27.09.2022 23:15:15
  • Zuletzt bearbeitet 21.05.2025 15:15:57

Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules.

Exploit
  • EPSS 1.28%
  • Veröffentlicht 29.04.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 05:13:25

An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.

Exploit
  • EPSS 3.61%
  • Veröffentlicht 20.01.2021 01:15:13
  • Zuletzt bearbeitet 21.11.2024 05:09:09

Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.