Show filters
66 Total Results
Displaying 1-10 of 66
Sort by:
Attacker Value
Unknown
CVE-2025-1618
Disclosure Date: February 24, 2025 (last updated February 24, 2025)
A vulnerability has been found in vTiger CRM 6.4.0 and classified as problematic. This vulnerability affects unknown code of the file /modules/Mobile/index.php. The manipulation of the argument _operation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-48119
Disclosure Date: October 14, 2024 (last updated October 31, 2024)
Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.
0
Attacker Value
Unknown
CVE-2024-44779
Disclosure Date: August 29, 2024 (last updated September 04, 2024)
A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
0
Attacker Value
Unknown
CVE-2024-44778
Disclosure Date: August 29, 2024 (last updated September 04, 2024)
A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
0
Attacker Value
Unknown
CVE-2024-44777
Disclosure Date: August 29, 2024 (last updated September 04, 2024)
A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
0
Attacker Value
Unknown
CVE-2024-44776
Disclosure Date: August 29, 2024 (last updated September 04, 2024)
An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.
0
Attacker Value
Unknown
CVE-2023-38891
Disclosure Date: September 14, 2023 (last updated October 08, 2023)
SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.
0
Attacker Value
Unknown
CVE-2022-38335
Disclosure Date: September 27, 2022 (last updated February 24, 2025)
Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules.
0
Attacker Value
Unknown
CVE-2020-22807
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.
0
Attacker Value
Unknown
CVE-2020-19362
Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page.
0