Show filters
717 Total Results
Displaying 231-240 of 717
Sort by:
Attacker Value
Unknown
CVE-2022-3955
Disclosure Date: November 11, 2022 (last updated February 24, 2025)
A vulnerability was found in tholum crm42. It has been rated as critical. This issue affects some unknown processing of the file crm42\class\class.user.php of the component Login. The manipulation of the argument user_name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-213461 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2021-40303
Disclosure Date: November 08, 2022 (last updated February 24, 2025)
perfex crm 1.10 is vulnerable to Cross Site Scripting (XSS) via /clients/profile.
0
Attacker Value
Unknown
CVE-2022-41978
Disclosure Date: October 27, 2022 (last updated February 24, 2025)
Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress.
0
Attacker Value
Unknown
CVE-2022-40871
Disclosure Date: October 12, 2022 (last updated February 24, 2025)
Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.
0
Attacker Value
Unknown
CVE-2022-39281
Disclosure Date: October 08, 2022 (last updated February 24, 2025)
fat_free_crm is a an open source, Ruby on Rails customer relationship management platform (CRM). In versions prior to 0.20.1 an authenticated user can perform a remote Denial of Service attack against Fat Free CRM via bucket access. The vulnerability has been patched in commit `c85a254` and will be available in release `0.20.1`. Users are advised to upgrade or to manually apply patch `c85a254`. There are no known workarounds for this issue.
0
Attacker Value
Unknown
CVE-2022-38335
Disclosure Date: September 27, 2022 (last updated February 24, 2025)
Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules.
0
Attacker Value
Unknown
CVE-2022-38846
Disclosure Date: September 16, 2022 (last updated February 24, 2025)
EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attacker may capture the cookie from the insecure channel using MITM attack.
0
Attacker Value
Unknown
CVE-2022-38845
Disclosure Date: September 16, 2022 (last updated February 24, 2025)
Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafted csv file containing malicious JavaScript to authenticated user. Any authenticated user importing the crafted CSV file may end up running the malicious JavaScripting in the browser.
0
Attacker Value
Unknown
CVE-2022-38844
Disclosure Date: September 16, 2022 (last updated February 24, 2025)
CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capable of executing system commands. Admin user exporting contacts in CSV file may end up executing the malicious system commands on his system.
0
Attacker Value
Unknown
CVE-2022-38843
Disclosure Date: September 16, 2022 (last updated February 24, 2025)
EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacker may execute these malicious files to run unintended code on the server to compromise the server.
0