Show filters
146 Total Results
Displaying 41-50 of 146
Sort by:
Attacker Value
Unknown

CVE-2023-24654

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Request a Quote function.
Attacker Value
Unknown

CVE-2023-24653

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the oldpass parameter under the Change Password function.
Attacker Value
Unknown

CVE-2023-24652

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Description parameter under the Create ticket function.
Attacker Value
Unknown

CVE-2023-24651

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter on the registration page.
Attacker Value
Unknown

CVE-2023-24364

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter under the Admin Panel.
Attacker Value
Unknown

CVE-2023-0917

Disclosure Date: February 19, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as critical, was found in SourceCodester Simple Customer Relationship Management System 1.0. This affects an unknown part of the file /php-scrm/login.php. The manipulation of the argument Password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221493 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-24525

Disclosure Date: February 14, 2023 (last updated October 08, 2023)
SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an authenticated attacker can cause limited impact on confidentiality of the application.
Attacker Value
Unknown

CVE-2022-3002

Disclosure Date: October 06, 2022 (last updated December 22, 2024)
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
Attacker Value
Unknown

CVE-2022-3005

Disclosure Date: September 20, 2022 (last updated October 08, 2023)
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
Attacker Value
Unknown

CVE-2022-3004

Disclosure Date: September 20, 2022 (last updated October 08, 2023)
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.