Show filters
718 Total Results
Displaying 441-450 of 718
Sort by:
Attacker Value
Unknown

CVE-2019-10226

Disclosure Date: June 10, 2019 (last updated February 22, 2024)
HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is a XSS protection mechanism.
0
Attacker Value
Unknown

CVE-2019-12599

Disclosure Date: June 07, 2019 (last updated November 27, 2024)
SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection.
0
Attacker Value
Unknown

CVE-2019-12598

Disclosure Date: June 07, 2019 (last updated November 27, 2024)
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3).
0
Attacker Value
Unknown

CVE-2019-12600

Disclosure Date: June 07, 2019 (last updated November 27, 2024)
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3).
0
Attacker Value
Unknown

CVE-2019-12601

Disclosure Date: June 07, 2019 (last updated November 27, 2024)
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 3 of 3).
0
Attacker Value
Unknown

CVE-2018-8047

Disclosure Date: June 06, 2019 (last updated November 27, 2024)
vtiger CRM 7.0.1 is affected by one reflected Cross-Site Scripting (XSS) vulnerability affecting version 7.0.1 and probably prior versions. This vulnerability could allow remote unauthenticated attackers to inject arbitrary web script or HTML via index.php?module=Contacts&view=List (app parameter).
0
Attacker Value
Unknown

CVE-2016-10754

Disclosure Date: May 24, 2019 (last updated November 27, 2024)
modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.
0
Attacker Value
Unknown

CVE-2019-11057

Disclosure Date: May 17, 2019 (last updated November 08, 2023)
SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.
Attacker Value
Unknown

CVE-2019-1008

Disclosure Date: May 16, 2019 (last updated November 27, 2024)
A security feature bypass vulnerability exists in Dynamics On Premise, aka 'Microsoft Dynamics On-Premise Security Feature Bypass'.
0
Attacker Value
Unknown

CVE-2019-2675

Disclosure Date: April 23, 2019 (last updated November 27, 2024)
Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Preferences). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
0