Show filters
102 Total Results
Displaying 11-20 of 102
Sort by:
Attacker Value
Unknown

CVE-2023-34548

Disclosure Date: June 16, 2023 (last updated October 08, 2023)
Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter.
Attacker Value
Unknown

CVE-2023-33986

Disclosure Date: June 13, 2023 (last updated October 08, 2023)
SAP CRM ABAP (Grantor Management) - versions 700, 701, 702, 712, 713, 714, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application.
Attacker Value
Unknown

CVE-2023-3058

Disclosure Date: June 02, 2023 (last updated October 08, 2023)
A vulnerability was found in 07FLY CRM up to 1.2.0. It has been declared as problematic. This vulnerability affects unknown code of the component User Profile Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230560.
Attacker Value
Unknown

CVE-2023-30742

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
SAP CRM (WebClient UI) - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 700, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scripting (XSS) vulnerability.An attacker could store a malicious URL and lure the victim to click, causing the script supplied by the attacker to execute in the victim user's session. The information from the victim's session could then be modified or read by the attacker.
Attacker Value
Unknown

CVE-2023-29188

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
SAP CRM WebClient UI - versions SAPSCORE 129, S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker with user level access can read and modify some sensitive information but cannot delete the data.
Attacker Value
Unknown

CVE-2023-29189

Disclosure Date: April 11, 2023 (last updated October 08, 2023)
SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 801, allows an authenticated attacker to modify HTTP verbs used in requests to the web server. This application is exposed over the network and successful exploitation can lead to exposure of form fields
Attacker Value
Unknown

CVE-2023-27897

Disclosure Date: April 11, 2023 (last updated October 08, 2023)
In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can can have limited impact on confidentiality and integrity of non-critical user or application data and application availability.
Attacker Value
Unknown

CVE-2023-24655

Disclosure Date: March 23, 2023 (last updated October 08, 2023)
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function.
Attacker Value
Unknown

CVE-2023-24732

Disclosure Date: March 15, 2023 (last updated October 08, 2023)
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the gender parameter in the user profile update function.
Attacker Value
Unknown

CVE-2023-24731

Disclosure Date: March 15, 2023 (last updated October 08, 2023)
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the query parameter in the user profile update function.