Show filters
65 Total Results
Displaying 1-10 of 65
Sort by:
Attacker Value
Unknown
CVE-2024-48119
Disclosure Date: October 14, 2024 (last updated October 31, 2024)
Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.
0
Attacker Value
Unknown
CVE-2024-44779
Disclosure Date: August 29, 2024 (last updated September 04, 2024)
A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
0
Attacker Value
Unknown
CVE-2024-44778
Disclosure Date: August 29, 2024 (last updated September 04, 2024)
A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
0
Attacker Value
Unknown
CVE-2024-44777
Disclosure Date: August 29, 2024 (last updated September 04, 2024)
A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
0
Attacker Value
Unknown
CVE-2024-44776
Disclosure Date: August 29, 2024 (last updated September 04, 2024)
An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.
0
Attacker Value
Unknown
CVE-2023-38891
Disclosure Date: September 14, 2023 (last updated October 08, 2023)
SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.
0
Attacker Value
Unknown
CVE-2022-38335
Disclosure Date: September 27, 2022 (last updated October 08, 2023)
Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules.
0
Attacker Value
Unknown
CVE-2020-22807
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.
0
Attacker Value
Unknown
CVE-2020-19362
Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page.
0
Attacker Value
Unknown
CVE-2020-19363
Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.
0