Vtiger

Vtiger Crm

74 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 40.24%
  • Veröffentlicht 06.02.2020 14:15:10
  • Zuletzt bearbeitet 21.11.2024 02:34:16

Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by upl...

  • EPSS 68.85%
  • Veröffentlicht 29.01.2020 18:15:12
  • Zuletzt bearbeitet 21.11.2024 01:53:11

vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.

Exploit
  • EPSS 84.54%
  • Veröffentlicht 28.01.2020 21:15:11
  • Zuletzt bearbeitet 21.11.2024 01:53:11

vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.

Exploit
  • EPSS 7.54%
  • Veröffentlicht 28.01.2020 21:15:11
  • Zuletzt bearbeitet 21.11.2024 01:53:11

vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.

Exploit
  • EPSS 1%
  • Veröffentlicht 21.11.2019 20:15:15
  • Zuletzt bearbeitet 21.11.2024 04:34:19

In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request.

  • EPSS 1.28%
  • Veröffentlicht 06.06.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:13:11

vtiger CRM 7.0.1 is affected by one reflected Cross-Site Scripting (XSS) vulnerability affecting version 7.0.1 and probably prior versions. This vulnerability could allow remote unauthenticated attackers to inject arbitrary web script or HTML via ind...

Exploit
  • EPSS 1.46%
  • Veröffentlicht 24.05.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 02:44:40

modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.

Exploit
  • EPSS 1.21%
  • Veröffentlicht 17.05.2019 17:29:00
  • Zuletzt bearbeitet 21.11.2024 04:20:27

SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.

Exploit
  • EPSS 9.94%
  • Veröffentlicht 04.01.2019 14:29:00
  • Zuletzt bearbeitet 21.11.2024 04:44:10

Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and has a size of 150x40. One can put PHP code into the image; PHP code can be executed using "<? ?>" tag...

Exploit
  • EPSS 16.56%
  • Veröffentlicht 14.04.2017 18:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows remote authenticated users to execute arbitrary code by uploading a cra...