VYPR

Client Relationship Management

by Oroinc

Source repositories

CVEs (2)

  • CVE-2021-39198MedNov 19, 2021
    risk 0.27cvss 4.2epss 0.00

    OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross-Site Request Forgery (CSRF) attack. There are no workarounds that address this…

  • CVE-2023-32063MedNov 28, 2023
    risk 0.26cvss 5.0epss 0.01

    OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.4 and…