Show filters
718 Total Results
Displaying 431-440 of 718
Sort by:
Attacker Value
Unknown
CVE-2019-14349
Disclosure Date: July 28, 2019 (last updated November 27, 2024)
EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for storing documents in the account tab. An attacker can upload a crafted file that contains JavaScript code in its name. This code will be executed when a user opens a page of any profile with this.
0
Attacker Value
Unknown
CVE-2019-14331
Disclosure Date: July 28, 2019 (last updated November 27, 2024)
An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create User. A malicious attacker can modify the firstName and lastName to contain JavaScript code.
0
Attacker Value
Unknown
CVE-2019-14329
Disclosure Date: July 28, 2019 (last updated November 27, 2024)
An issue was discovered in EspoCRM before 5.6.6. There is stored XSS due to lack of filtration of user-supplied data in Create Task. A malicious attacker can modify the parameter name to contain JavaScript code.
0
Attacker Value
Unknown
CVE-2019-14330
Disclosure Date: July 28, 2019 (last updated November 27, 2024)
An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create Case. A malicious attacker can modify the firstName and lastName to contain JavaScript code.
0
Attacker Value
Unknown
CVE-2019-2837
Disclosure Date: July 23, 2019 (last updated November 27, 2024)
Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
0
Attacker Value
Unknown
CVE-2019-1010054
Disclosure Date: July 18, 2019 (last updated November 27, 2024)
Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disable password encryptation. The component is: Function User password change, user disable and password encryptation. The attack vector is: admin access malitious urls.
0
Attacker Value
Unknown
CVE-2019-13643
Disclosure Date: July 18, 2019 (last updated November 27, 2024)
Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target pages. The attack begins by storing a new stream message containing an XSS payload. The stored payload can then be triggered by clicking a malicious link on the Notifications page.
0
Attacker Value
Unknown
CVE-2019-19206
Disclosure Date: July 17, 2019 (last updated November 08, 2023)
Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture.
0
Attacker Value
Unknown
CVE-2019-1010016
Disclosure Date: July 15, 2019 (last updated November 27, 2024)
Dolibarr 6.0.4 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing. The component is: htdocs/product/stats/card.php. The attack vector is: Victim must click a specially crafted link sent by the attacker.
0
Attacker Value
Unknown
CVE-2019-10226
Disclosure Date: June 10, 2019 (last updated February 22, 2024)
HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is a XSS protection mechanism.
0