Show filters
717 Total Results
Displaying 131-140 of 717
Sort by:
Attacker Value
Unknown

CVE-2023-45394

Disclosure Date: October 20, 2023 (last updated February 25, 2025)
Stored Cross-Site Scripting (XSS) vulnerability in the Company field in the "Request a Quote" Section of Small CRM v3.0 allows an attacker to store and execute malicious javascript code in the Admin panel which leads to Admin account takeover.
Attacker Value
Unknown

CVE-2023-44075

Disclosure Date: October 04, 2023 (last updated February 25, 2025)
Cross Site Scripting vulnerability in Small CRM in PHP v.3.0 allows a remote attacker to execute arbitrary code via a crafted payload to the Address parameter.
Attacker Value
Unknown

CVE-2023-5353

Disclosure Date: October 03, 2023 (last updated February 25, 2025)
Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.
Attacker Value
Unknown

CVE-2023-5351

Disclosure Date: October 03, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.
Attacker Value
Unknown

CVE-2023-5350

Disclosure Date: October 03, 2023 (last updated February 25, 2025)
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.
Attacker Value
Unknown

CVE-2023-5323

Disclosure Date: October 01, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0.
Attacker Value
Unknown

CVE-2023-43331

Disclosure Date: September 27, 2023 (last updated February 25, 2025)
A cross-site scripting (XSS) vulnerability in the Add User function of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Attacker Value
Unknown

CVE-2023-38888

Disclosure Date: September 20, 2023 (last updated February 25, 2025)
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
Attacker Value
Unknown

CVE-2023-38887

Disclosure Date: September 20, 2023 (last updated February 25, 2025)
File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions.
Attacker Value
Unknown

CVE-2023-38886

Disclosure Date: September 20, 2023 (last updated February 25, 2025)
An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.