Vtiger

Vtiger Crm

76 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.75%
  • Veröffentlicht 20.01.2021 01:15:13
  • Zuletzt bearbeitet 21.11.2024 05:09:09

Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page.

Exploit
  • EPSS 43.1%
  • Veröffentlicht 07.02.2020 15:15:10
  • Zuletzt bearbeitet 21.11.2024 01:53:56

vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability

Exploit
  • EPSS 40.24%
  • Veröffentlicht 06.02.2020 14:15:10
  • Zuletzt bearbeitet 21.11.2024 02:34:16

Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by upl...

  • EPSS 68.85%
  • Veröffentlicht 29.01.2020 18:15:12
  • Zuletzt bearbeitet 21.11.2024 01:53:11

vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.

Exploit
  • EPSS 84.54%
  • Veröffentlicht 28.01.2020 21:15:11
  • Zuletzt bearbeitet 21.11.2024 01:53:11

vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.

Exploit
  • EPSS 7.54%
  • Veröffentlicht 28.01.2020 21:15:11
  • Zuletzt bearbeitet 21.11.2024 01:53:11

vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.

Exploit
  • EPSS 1%
  • Veröffentlicht 21.11.2019 20:15:15
  • Zuletzt bearbeitet 21.11.2024 04:34:19

In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request.

  • EPSS 1.28%
  • Veröffentlicht 06.06.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:13:11

vtiger CRM 7.0.1 is affected by one reflected Cross-Site Scripting (XSS) vulnerability affecting version 7.0.1 and probably prior versions. This vulnerability could allow remote unauthenticated attackers to inject arbitrary web script or HTML via ind...

Exploit
  • EPSS 1.46%
  • Veröffentlicht 24.05.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 02:44:40

modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.

Exploit
  • EPSS 1.21%
  • Veröffentlicht 17.05.2019 17:29:00
  • Zuletzt bearbeitet 21.11.2024 04:20:27

SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.