VYPR

by Espocrm

Source repositories

CVEs (22)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2014-79850.000.02Oct 31, 2014Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter to install/index.php.
CVE-2014-83300.000.00Oct 20, 2014Cross-site scripting (XSS) vulnerability in EspoCRM allows remote authenticated users to inject arbitrary web script or HTML via the Name field in a new account.

Page 2 of 2