VYPR

Crm

by Perfexcrm

CVEs (5)

  • CVE-2016-4834HigAug 1, 2016
    risk 0.53cvss 8.1epss 0.01

    modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticated users to create or modify user accounts via unspecified vectors.

  • CVE-2017-17976Jan 26, 2018
    risk 0.04cvss epss 0.17

    In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.

  • CVE-2014-10009Jan 13, 2015
    risk 0.03cvss epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in Stark CRM 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, or (3) notes parameter to the client page; (4) insu_name or (5) price parameter to the add_insurance_cat…

  • CVE-2013-3213Apr 2, 2014
    risk 0.03cvss epss 0.00

    Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) picklist_name parameter in the get_picklists method to soap/customerportal.php, (2) where parameter in the get_tickets_list method to…

  • CVE-2024-8867Sep 15, 2024
    risk 0.00cvss epss 0.00

    A vulnerability was found in Perfex CRM 3.1.6. It has been declared as problematic. This vulnerability affects unknown code of the file application/controllers/Clients.php of the component Parameter Handler. The manipulation of the argument message leads to cross site scripting.…