Show filters
717 Total Results
Displaying 111-120 of 717
Sort by:
Attacker Value
Unknown

CVE-2023-48118

Disclosure Date: January 22, 2024 (last updated January 30, 2024)
SQL Injection vulnerability in Quest Analytics LLC IQCRM v.2023.9.5 allows a remote attacker to execute arbitrary code via a crafted request to the Common.svc WSDL page.
Attacker Value
Unknown

CVE-2023-50035

Disclosure Date: December 29, 2023 (last updated January 06, 2024)
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is directly used in the SQL query without any sanitization and the SQL Injection payload being executed.
Attacker Value
Unknown

CVE-2023-38481

Disclosure Date: December 19, 2023 (last updated December 23, 2023)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin.This issue affects Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin: from n/a before 1.3.7.
Attacker Value
Unknown

CVE-2023-46736

Disclosure Date: December 05, 2023 (last updated December 13, 2023)
EspoCRM is an Open Source CRM (Customer Relationship Management) software. In affected versions there is Server-Side Request Forgery (SSRF) vulnerability via the upload image from url api. Users who have access to `the /Attachment/fromImageUrl` endpoint can specify URL to point to an internal host. Even though there is check for content type, it can be bypassed by redirects in some cases. This SSRF can be leveraged to disclose internal information (in some cases), target internal hosts and bypass firewalls. This vulnerability has been addressed in commit `c536cee63` which is included in release version 8.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Attacker Value
Unknown

CVE-2023-5966

Disclosure Date: November 30, 2023 (last updated December 07, 2023)
An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, which could lead to arbitrary PHP code execution.
Attacker Value
Unknown

CVE-2023-5965

Disclosure Date: November 30, 2023 (last updated December 07, 2023)
An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the update form, which could lead to arbitrary PHP code execution.
Attacker Value
Unknown

CVE-2023-47643

Disclosure Date: November 21, 2023 (last updated November 29, 2023)
SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection is enabled without authentication, exposing the scheme defining all object types, arguments, and functions. An attacker can obtain the GraphQL schema and understand the entire attack surface of the API, including sensitive fields such as UserHash. This issue is patched in version 8.4.2. There are no known workarounds.
Attacker Value
Unknown

CVE-2023-6131

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Attacker Value
Unknown

CVE-2023-6130

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Attacker Value
Unknown

CVE-2023-6128

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.