Show filters
66 Total Results
Displaying 1-10 of 66
Sort by:
Attacker Value
Unknown

CVE-2025-1618

Disclosure Date: February 24, 2025 (last updated February 24, 2025)
A vulnerability has been found in vTiger CRM 6.4.0 and classified as problematic. This vulnerability affects unknown code of the file /modules/Mobile/index.php. The manipulation of the argument _operation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-48119

Disclosure Date: October 14, 2024 (last updated October 31, 2024)
Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.
Attacker Value
Unknown

CVE-2024-44779

Disclosure Date: August 29, 2024 (last updated September 04, 2024)
A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
Attacker Value
Unknown

CVE-2024-44778

Disclosure Date: August 29, 2024 (last updated September 04, 2024)
A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
Attacker Value
Unknown

CVE-2024-44777

Disclosure Date: August 29, 2024 (last updated September 04, 2024)
A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
Attacker Value
Unknown

CVE-2024-44776

Disclosure Date: August 29, 2024 (last updated September 04, 2024)
An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.
Attacker Value
Unknown

CVE-2023-38891

Disclosure Date: September 14, 2023 (last updated October 08, 2023)
SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.
Attacker Value
Unknown

CVE-2022-38335

Disclosure Date: September 27, 2022 (last updated February 24, 2025)
Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules.
Attacker Value
Unknown

CVE-2020-22807

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.
Attacker Value
Unknown

CVE-2020-19362

Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page.