Show filters
717 Total Results
Displaying 191-200 of 717
Sort by:
Attacker Value
Unknown
CVE-2023-2419
Disclosure Date: April 29, 2023 (last updated February 24, 2025)
A vulnerability was found in Zhong Bang CRMEB 4.6.0. It has been declared as critical. This vulnerability affects the function videoUpload of the file \crmeb\app\services\system\attachment\SystemAttachmentServices.php. The manipulation of the argument filename leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-227716.
0
Attacker Value
Unknown
CVE-2023-26843
Disclosure Date: April 25, 2023 (last updated February 24, 2025)
A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the NoteEditor.php.
0
Attacker Value
Unknown
CVE-2023-26841
Disclosure Date: April 25, 2023 (last updated February 24, 2025)
A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to change any user's password except for the user that is currently logged in.
0
Attacker Value
Unknown
CVE-2023-26840
Disclosure Date: April 25, 2023 (last updated February 24, 2025)
A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to set a person to a user and set that user to be an Administrator.
0
Attacker Value
Unknown
CVE-2023-26839
Disclosure Date: April 25, 2023 (last updated February 24, 2025)
A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to edit information for existing people on the site.
0
Attacker Value
Unknown
CVE-2023-25348
Disclosure Date: April 25, 2023 (last updated February 24, 2025)
ChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new person. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.
0
Attacker Value
Unknown
CVE-2023-25347
Disclosure Date: April 25, 2023 (last updated February 24, 2025)
A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Input Field in EventEditor.php.
0
Attacker Value
Unknown
CVE-2023-25346
Disclosure Date: April 25, 2023 (last updated February 24, 2025)
A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter of /churchcrm/v2/family/not-found.
0
Attacker Value
Unknown
CVE-2022-44582
Disclosure Date: April 23, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Apptivo Apptivo Business Site CRM plugin <= 3.0.12 versions.
0
Attacker Value
Unknown
CVE-2023-21909
Disclosure Date: April 18, 2023 (last updated October 08, 2023)
Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: UI Framework). Supported versions that are affected are 23.3 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
0