CVE-2023-46304
- EPSS 20.76%
- Veröffentlicht 30.04.2024 13:15:46
- Zuletzt bearbeitet 22.04.2025 17:53:58
modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).
CVE-2023-38891
- EPSS 1.87%
- Veröffentlicht 14.09.2023 23:15:07
- Zuletzt bearbeitet 21.11.2024 08:14:23
SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.
CVE-2022-38335
- EPSS 0.51%
- Veröffentlicht 27.09.2022 23:15:15
- Zuletzt bearbeitet 21.05.2025 15:15:57
Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules.
CVE-2020-22807
- EPSS 0.26%
- Veröffentlicht 29.04.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 05:13:25
An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.
CVE-2020-19363
- EPSS 0.41%
- Veröffentlicht 20.01.2021 01:15:13
- Zuletzt bearbeitet 21.11.2024 05:09:09
Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.
CVE-2020-19362
- EPSS 0.24%
- Veröffentlicht 20.01.2021 01:15:13
- Zuletzt bearbeitet 21.11.2024 05:09:09
Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page.
CVE-2013-3591
- EPSS 79.9%
- Veröffentlicht 07.02.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 01:53:56
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
CVE-2015-6000
- EPSS 77.42%
- Veröffentlicht 06.02.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 02:34:16
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by upl...
CVE-2013-3215
- EPSS 73.67%
- Veröffentlicht 29.01.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 01:53:11
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.
CVE-2013-3214
- EPSS 88.54%
- Veröffentlicht 28.01.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 01:53:11
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.