Show filters
717 Total Results
Displaying 141-150 of 717
Sort by:
Attacker Value
Unknown

CVE-2023-38891

Disclosure Date: September 14, 2023 (last updated February 25, 2025)
SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.
Attacker Value
Unknown

CVE-2023-41150

Disclosure Date: September 06, 2023 (last updated February 25, 2025)
F-RevoCRM 7.3 series prior to version7.3.8 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product.
Attacker Value
Unknown

CVE-2023-41149

Disclosure Date: September 06, 2023 (last updated February 25, 2025)
F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploited, an attacker who can access the product may execute an arbitrary OS command on the server where the product is running.
Attacker Value
Unknown

CVE-2020-28849

Disclosure Date: August 11, 2023 (last updated February 25, 2025)
Cross Site Scripting (XSS) vulnerability in ChurchCRM version 4.2.1, allows remote attckers to execute arbitrary code and gain sensitive information via crafted payload in Add New Deposit field in View All Deposit module.
Attacker Value
Unknown

CVE-2020-28848

Disclosure Date: August 11, 2023 (last updated February 25, 2025)
CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CSV file.
Attacker Value
Unknown

CVE-2022-44629

Disclosure Date: August 10, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Catalyst Connect Catalyst Connect Zoho CRM Client Portal plugin <= 2.0.0 versions.
Attacker Value
Unknown

CVE-2023-38773

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the volopp1 and volopp2 parameters within the /QueryView.php.
Attacker Value
Unknown

CVE-2023-38771

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the volopp parameter within the /QueryView.php.
Attacker Value
Unknown

CVE-2023-38770

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the group parameter within the /QueryView.php.
Attacker Value
Unknown

CVE-2023-38769

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the searchstring and searchwhat parameters within the /QueryView.php.