Show filters
66 Total Results
Displaying 11-20 of 66
Sort by:
Attacker Value
Unknown
CVE-2020-19363
Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.
0
Attacker Value
Unknown
CVE-2013-3591
Disclosure Date: February 07, 2020 (last updated February 21, 2025)
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2015-6000
Disclosure Date: February 06, 2020 (last updated February 21, 2025)
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in test/logo/.
0
Attacker Value
Unknown
CVE-2013-3215
Disclosure Date: January 29, 2020 (last updated February 21, 2025)
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.
0
Attacker Value
Unknown
CVE-2013-3212
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.
0
Attacker Value
Unknown
CVE-2013-3214
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
0
Attacker Value
Unknown
CVE-2019-19202
Disclosure Date: November 21, 2019 (last updated November 27, 2024)
In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request.
0
Attacker Value
Unknown
CVE-2018-8047
Disclosure Date: June 06, 2019 (last updated November 27, 2024)
vtiger CRM 7.0.1 is affected by one reflected Cross-Site Scripting (XSS) vulnerability affecting version 7.0.1 and probably prior versions. This vulnerability could allow remote unauthenticated attackers to inject arbitrary web script or HTML via index.php?module=Contacts&view=List (app parameter).
0
Attacker Value
Unknown
CVE-2016-10754
Disclosure Date: May 24, 2019 (last updated November 27, 2024)
modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.
0
Attacker Value
Unknown
CVE-2019-11057
Disclosure Date: May 17, 2019 (last updated November 08, 2023)
SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.
0