Show filters
717 Total Results
Displaying 191-200 of 717
Sort by:
Attacker Value
Unknown

CVE-2023-2419

Disclosure Date: April 29, 2023 (last updated February 24, 2025)
A vulnerability was found in Zhong Bang CRMEB 4.6.0. It has been declared as critical. This vulnerability affects the function videoUpload of the file \crmeb\app\services\system\attachment\SystemAttachmentServices.php. The manipulation of the argument filename leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-227716.
Attacker Value
Unknown

CVE-2023-26843

Disclosure Date: April 25, 2023 (last updated February 24, 2025)
A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the NoteEditor.php.
Attacker Value
Unknown

CVE-2023-26841

Disclosure Date: April 25, 2023 (last updated February 24, 2025)
A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to change any user's password except for the user that is currently logged in.
Attacker Value
Unknown

CVE-2023-26840

Disclosure Date: April 25, 2023 (last updated February 24, 2025)
A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to set a person to a user and set that user to be an Administrator.
Attacker Value
Unknown

CVE-2023-26839

Disclosure Date: April 25, 2023 (last updated February 24, 2025)
A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to edit information for existing people on the site.
Attacker Value
Unknown

CVE-2023-25348

Disclosure Date: April 25, 2023 (last updated February 24, 2025)
ChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new person. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.
Attacker Value
Unknown

CVE-2023-25347

Disclosure Date: April 25, 2023 (last updated February 24, 2025)
A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Input Field in EventEditor.php.
Attacker Value
Unknown

CVE-2023-25346

Disclosure Date: April 25, 2023 (last updated February 24, 2025)
A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter of /churchcrm/v2/family/not-found.
Attacker Value
Unknown

CVE-2022-44582

Disclosure Date: April 23, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Apptivo Apptivo Business Site CRM plugin <= 3.0.12 versions.
Attacker Value
Unknown

CVE-2023-21909

Disclosure Date: April 18, 2023 (last updated October 08, 2023)
Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: UI Framework). Supported versions that are affected are 23.3 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).