Show filters
717 Total Results
Displaying 311-320 of 717
Sort by:
Attacker Value
Unknown
CVE-2020-35459
Disclosure Date: January 12, 2021 (last updated February 22, 2025)
An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.
0
Attacker Value
Unknown
CVE-2020-35136
Disclosure Date: December 23, 2020 (last updated February 22, 2025)
Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilename_template parameter to admin/tools/dolibarr_export.php.
0
Attacker Value
Unknown
CVE-2020-14208
Disclosure Date: November 18, 2020 (last updated February 22, 2025)
SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.
0
Attacker Value
Unknown
CVE-2020-15300
Disclosure Date: November 18, 2020 (last updated February 22, 2025)
SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document.
0
Attacker Value
Unknown
CVE-2020-15301
Disclosure Date: November 18, 2020 (last updated February 22, 2025)
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.
0
Attacker Value
Unknown
CVE-2020-7472
Disclosure Date: November 12, 2020 (last updated February 22, 2025)
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenticated remote code execution against a configured SugarCRM instance via crafted HTTP requests. (This is exploitable even after installation is completed.).
0
Attacker Value
Unknown
CVE-2020-17006
Disclosure Date: November 11, 2020 (last updated February 22, 2025)
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
0
Attacker Value
Unknown
CVE-2020-28328
Disclosure Date: November 06, 2020 (last updated February 22, 2025)
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.
0
Attacker Value
Unknown
CVE-2020-25466
Disclosure Date: October 23, 2020 (last updated February 22, 2025)
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.
0
Attacker Value
Unknown
CVE-2020-15958
Disclosure Date: September 18, 2020 (last updated February 22, 2025)
An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to access various sensitive information via an unauthenticated request with a predictable URL.
0