Show filters
102 Total Results
Displaying 21-30 of 102
Sort by:
Attacker Value
Unknown

CVE-2023-24730

Disclosure Date: March 15, 2023 (last updated October 08, 2023)
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the company parameter in the user profile update function.
Attacker Value
Unknown

CVE-2023-24729

Disclosure Date: March 15, 2023 (last updated October 08, 2023)
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the address parameter in the user profile update function.
Attacker Value
Unknown

CVE-2023-24728

Disclosure Date: March 15, 2023 (last updated October 08, 2023)
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the contact parameter in the user profile update function.
Attacker Value
Unknown

CVE-2023-24656

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the subject parameter under the Create Ticket function.
Attacker Value
Unknown

CVE-2023-24654

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Request a Quote function.
Attacker Value
Unknown

CVE-2023-24653

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the oldpass parameter under the Change Password function.
Attacker Value
Unknown

CVE-2023-24652

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Description parameter under the Create ticket function.
Attacker Value
Unknown

CVE-2023-24651

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter on the registration page.
Attacker Value
Unknown

CVE-2023-24364

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter under the Admin Panel.
Attacker Value
Unknown

CVE-2023-0917

Disclosure Date: February 19, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as critical, was found in SourceCodester Simple Customer Relationship Management System 1.0. This affects an unknown part of the file /php-scrm/login.php. The manipulation of the argument Password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221493 was assigned to this vulnerability.