VYPR

Daybyday

by DaybydayCRM

CVEs (6)

  • CVE-2022-22113HigJan 13, 2022
    risk 0.57cvss 8.8epss 0.01

    In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was…

  • CVE-2022-22112MedJan 13, 2022
    risk 0.35cvss 5.4epss 0.01

    In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CSTI). A low privileged attacker can input template injection payloads in the application at various locations to execute JavaScript on the client browser.

  • CVE-2020-35707MedDec 25, 2020
    risk 0.35cvss 5.4epss 0.01

    Daybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen.

  • CVE-2020-35706MedDec 25, 2020
    risk 0.35cvss 5.4epss 0.01

    Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Project screen.

  • CVE-2020-35705MedDec 25, 2020
    risk 0.35cvss 5.4epss 0.01

    Daybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen.

  • CVE-2020-35704MedDec 25, 2020
    risk 0.35cvss 5.4epss 0.01

    Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Lead screen.