Show filters
717 Total Results
Displaying 61-70 of 717
Sort by:
Attacker Value
Unknown
CVE-2024-45392
Disclosure Date: September 05, 2024 (last updated September 07, 2024)
SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Versions 7.14.5 and 8.6.2 contain a patch for the issue.
0
Attacker Value
Unknown
CVE-2024-44779
Disclosure Date: August 29, 2024 (last updated September 04, 2024)
A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
0
Attacker Value
Unknown
CVE-2024-44778
Disclosure Date: August 29, 2024 (last updated September 04, 2024)
A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
0
Attacker Value
Unknown
CVE-2024-44777
Disclosure Date: August 29, 2024 (last updated September 04, 2024)
A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
0
Attacker Value
Unknown
CVE-2024-44776
Disclosure Date: August 29, 2024 (last updated September 04, 2024)
An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.
0
Attacker Value
Unknown
CVE-2024-43350
Disclosure Date: August 18, 2024 (last updated August 19, 2024)
Authorization Bypass Through User-Controlled Key vulnerability in Propovoice Propovoice CRM.This issue affects Propovoice CRM: from n/a through 1.7.6.4.
0
Attacker Value
Unknown
CVE-2024-41737
Disclosure Date: August 13, 2024 (last updated September 13, 2024)
SAP CRM ABAP (Insights
Management) allows an authenticated attacker to enumerate HTTP endpoints in the
internal network by specially crafting HTTP requests. On successful
exploitation this can result in information disclosure. It has no impact on
integrity and availability of the application.
0
Attacker Value
Unknown
CVE-2024-41309
Disclosure Date: August 07, 2024 (last updated August 09, 2024)
An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.
0
Attacker Value
Unknown
CVE-2024-41308
Disclosure Date: August 07, 2024 (last updated August 09, 2024)
An issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.
0
Attacker Value
Unknown
CVE-2024-38166
Disclosure Date: August 06, 2024 (last updated August 13, 2024)
An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link.
0