Show filters
717 Total Results
Displaying 311-320 of 717
Sort by:
Attacker Value
Unknown

CVE-2020-35459

Disclosure Date: January 12, 2021 (last updated February 22, 2025)
An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.
Attacker Value
Unknown

CVE-2020-35136

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilename_template parameter to admin/tools/dolibarr_export.php.
Attacker Value
Unknown

CVE-2020-14208

Disclosure Date: November 18, 2020 (last updated February 22, 2025)
SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.
Attacker Value
Unknown

CVE-2020-15300

Disclosure Date: November 18, 2020 (last updated February 22, 2025)
SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document.
Attacker Value
Unknown

CVE-2020-15301

Disclosure Date: November 18, 2020 (last updated February 22, 2025)
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.
Attacker Value
Unknown

CVE-2020-7472

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenticated remote code execution against a configured SugarCRM instance via crafted HTTP requests. (This is exploitable even after installation is completed.).
Attacker Value
Unknown

CVE-2020-17006

Disclosure Date: November 11, 2020 (last updated February 22, 2025)
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
0
Attacker Value
Unknown

CVE-2020-28328

Disclosure Date: November 06, 2020 (last updated February 22, 2025)
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.
Attacker Value
Unknown

CVE-2020-25466

Disclosure Date: October 23, 2020 (last updated February 22, 2025)
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.
Attacker Value
Unknown

CVE-2020-15958

Disclosure Date: September 18, 2020 (last updated February 22, 2025)
An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to access various sensitive information via an unauthenticated request with a predictable URL.