Show filters
717 Total Results
Displaying 161-170 of 717
Sort by:
Attacker Value
Unknown
CVE-2023-3562
Disclosure Date: July 10, 2023 (last updated February 25, 2025)
A vulnerability has been found in GZ Scripts PHP CRM Platform 1.8 and classified as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument action leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-233356. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-3529
Disclosure Date: July 06, 2023 (last updated February 25, 2025)
A vulnerability classified as problematic has been found in Rotem Dynamics Rotem CRM up to 20230729. This affects an unknown part of the file /LandingPages/api/otp/send?id=[ID][ampersand]method=sms of the component OTP URI Interface. The manipulation leads to information exposure through discrepancy. It is possible to initiate the attack remotely. The identifier VDB-233253 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-33661
Disclosure Date: June 29, 2023 (last updated February 25, 2025)
Multiple cross-site scripting (XSS) vulnerabilities were discovered in Church CRM v4.5.3 in GroupReports.php via GroupRole, ReportModel, and OnlyCart parameters.
0
Attacker Value
Unknown
CVE-2023-34650
Disclosure Date: June 28, 2023 (last updated February 25, 2025)
PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Scripting (XSS).
0
Attacker Value
Unknown
CVE-2023-0588
Disclosure Date: June 27, 2023 (last updated October 08, 2023)
The Catalyst Connect Zoho CRM Client Portal WordPress plugin before 2.1.0 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admin.
0
Attacker Value
Unknown
CVE-2023-27427
Disclosure Date: June 23, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NTZApps CRM Memberships plugin <= 1.6 versions.
0
Attacker Value
Unknown
CVE-2023-27429
Disclosure Date: June 21, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Automattic - Jetpack CRM team Jetpack CRM plugin <= 5.4.4 versions.
0
Attacker Value
Unknown
CVE-2023-2527
Disclosure Date: June 19, 2023 (last updated February 25, 2025)
The Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before 1.2.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
0
Attacker Value
Unknown
CVE-2023-35811
Disclosure Date: June 17, 2023 (last updated February 25, 2025)
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. Two SQL Injection vectors have been identified in the REST API. By using crafted requests, custom SQL code can be injected through the REST API because of missing input validation. Regular user privileges can use used for exploitation. Editions other than Enterprise are also affected.
0
Attacker Value
Unknown
CVE-2023-35810
Disclosure Date: June 17, 2023 (last updated February 25, 2025)
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Second-Order PHP Object Injection vulnerability has been identified in the DocuSign module. By using crafted requests, custom PHP code can be injected and executed through the DocuSign module because of missing input validation. Admin user privileges are required to exploit this vulnerability. Editions other than Enterprise are also affected.
0