Show filters
717 Total Results
Displaying 291-300 of 717
Sort by:
Attacker Value
Unknown

CVE-2021-25956

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account takeover of the victim user. This happens since the password gets overwritten for the victim user having a similar login name.
Attacker Value
Unknown

CVE-2021-3539

Disclosure Date: July 27, 2021 (last updated February 23, 2025)
EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 6.1.7 of the product.
Attacker Value
Unknown

CVE-2021-2368

Disclosure Date: July 21, 2021 (last updated November 28, 2024)
Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: Siebel Core - Server Infrastructure). Supported versions that are affected are 21.5 and Prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).
0
Attacker Value
Unknown

CVE-2020-21394

Disclosure Date: June 29, 2021 (last updated February 22, 2025)
SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php.
Attacker Value
Unknown

CVE-2020-21787

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.
Attacker Value
Unknown

CVE-2020-21788

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
In CRMEB 3.1.0+ strict domain name filtering leads to SSRF(Server-Side Request Forgery). The vulnerable code is in file /crmeb/app/admin/controller/store/CopyTaobao.php.
Attacker Value
Unknown

CVE-2020-36388

Disclosure Date: June 17, 2021 (last updated February 22, 2025)
In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR archive.
Attacker Value
Unknown

CVE-2020-36389

Disclosure Date: June 17, 2021 (last updated February 22, 2025)
In CiviCRM before 5.28.1 and CiviCRM ESR before 5.27.5 ESR, the CKEditor configuration form allows CSRF.
Attacker Value
Unknown

CVE-2021-31792

Disclosure Date: April 30, 2021 (last updated February 22, 2025)
XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field
Attacker Value
Unknown

CVE-2020-22807

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.