Show filters
717 Total Results
Displaying 401-410 of 717
Sort by:
Attacker Value
Unknown

CVE-2019-17316

Disclosure Date: October 07, 2019 (last updated November 27, 2024)
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user.
Attacker Value
Unknown

CVE-2019-17315

Disclosure Date: October 07, 2019 (last updated November 27, 2024)
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Administration module by an Admin user.
Attacker Value
Unknown

CVE-2019-17319

Disclosure Date: October 07, 2019 (last updated November 27, 2024)
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Emails module by a Regular user.
Attacker Value
Unknown

CVE-2019-17317

Disclosure Date: October 07, 2019 (last updated November 27, 2024)
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user.
Attacker Value
Unknown

CVE-2019-14454

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
SuiteCRM 7.11.x and 7.10.x before 7.11.8 and 7.10.20 is vulnerable to vertical privilege escalation.
Attacker Value
Unknown

CVE-2019-13335

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.
Attacker Value
Unknown

CVE-2019-14752

Disclosure Date: September 30, 2019 (last updated November 27, 2024)
SuiteCRM 7.10.x and 7.11.x before 7.10.20 and 7.11.8 has XSS.
Attacker Value
Unknown

CVE-2019-16685

Disclosure Date: September 27, 2019 (last updated November 27, 2024)
Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.
Attacker Value
Unknown

CVE-2019-16687

Disclosure Date: September 27, 2019 (last updated November 27, 2024)
Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.
Attacker Value
Unknown

CVE-2019-16686

Disclosure Date: September 27, 2019 (last updated November 27, 2024)
Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin.