Yetiforcecompany/yetiforcecrm
CVEs (17)
| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-3002 | 0.00 | — | 0.00 | Oct 6, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | ||
| CVE-2022-3005 | 0.00 | — | 0.00 | Sep 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | ||
| CVE-2022-3004 | 0.00 | — | 0.00 | Sep 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | ||
| CVE-2022-3000 | 0.00 | — | 0.00 | Sep 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | ||
| CVE-2022-2924 | 0.00 | — | 0.00 | Sep 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.3. | ||
| CVE-2022-2829 | 0.00 | — | 0.00 | Aug 23, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | ||
| CVE-2022-2890 | 0.00 | — | 0.00 | Aug 22, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | ||
| CVE-2022-1340 | 0.00 | — | 0.00 | Aug 22, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | ||
| CVE-2022-2885 | 0.00 | — | 0.00 | Aug 21, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | ||
| CVE-2022-1411 | 0.00 | — | 0.00 | May 5, 2022 | Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover. | ||
| CVE-2022-0269 | 0.00 | — | 0.00 | Jan 24, 2022 | Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0. | ||
| CVE-2021-4121 | 0.00 | — | 0.00 | Dec 16, 2021 | yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2021-4117 | 0.00 | — | 0.00 | Dec 15, 2021 | yetiforcecrm is vulnerable to Business Logic Errors | ||
| CVE-2021-4116 | 0.00 | — | 0.00 | Dec 15, 2021 | yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2021-4111 | 0.00 | — | 0.00 | Dec 15, 2021 | yetiforcecrm is vulnerable to Business Logic Errors | ||
| CVE-2021-4107 | 0.00 | — | 0.00 | Dec 14, 2021 | yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2021-4092 | 0.00 | — | 0.00 | Dec 11, 2021 | yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF) |
- CVE-2022-3002Oct 6, 2022risk 0.00cvss —epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
- CVE-2022-3005Sep 20, 2022risk 0.00cvss —epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
- CVE-2022-3004Sep 20, 2022risk 0.00cvss —epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
- CVE-2022-3000Sep 20, 2022risk 0.00cvss —epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
- CVE-2022-2924Sep 20, 2022risk 0.00cvss —epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.3.
- CVE-2022-2829Aug 23, 2022risk 0.00cvss —epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
- CVE-2022-2890Aug 22, 2022risk 0.00cvss —epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
- CVE-2022-1340Aug 22, 2022risk 0.00cvss —epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
- CVE-2022-2885Aug 21, 2022risk 0.00cvss —epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
- CVE-2022-1411May 5, 2022risk 0.00cvss —epss 0.00
Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover.
- CVE-2022-0269Jan 24, 2022risk 0.00cvss —epss 0.00
Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.
- CVE-2021-4121Dec 16, 2021risk 0.00cvss —epss 0.00
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2021-4117Dec 15, 2021risk 0.00cvss —epss 0.00
yetiforcecrm is vulnerable to Business Logic Errors
- CVE-2021-4116Dec 15, 2021risk 0.00cvss —epss 0.00
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2021-4111Dec 15, 2021risk 0.00cvss —epss 0.00
yetiforcecrm is vulnerable to Business Logic Errors
- CVE-2021-4107Dec 14, 2021risk 0.00cvss —epss 0.00
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2021-4092Dec 11, 2021risk 0.00cvss —epss 0.00
yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)