Crm
by Perfexcrm
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-4834 | Hig | 0.53 | 8.1 | 0.01 | Aug 1, 2016 | modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticated users to create or modify user accounts via unspecified vectors. | ||
| CVE-2017-17976 | 0.04 | — | 0.17 | Jan 26, 2018 | In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution. | |||
| CVE-2014-10009 | 0.03 | — | 0.03 | Jan 13, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Stark CRM 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, or (3) notes parameter to the client page; (4) insu_name or (5) price parameter to the add_insurance_cat… | |||
| CVE-2013-3213 | 0.03 | — | 0.00 | Apr 2, 2014 | Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) picklist_name parameter in the get_picklists method to soap/customerportal.php, (2) where parameter in the get_tickets_list method to… | |||
| CVE-2024-8867 | 0.00 | — | 0.00 | Sep 15, 2024 | A vulnerability was found in Perfex CRM 3.1.6. It has been declared as problematic. This vulnerability affects unknown code of the file application/controllers/Clients.php of the component Parameter Handler. The manipulation of the argument message leads to cross site scripting.… |
- risk 0.53cvss 8.1epss 0.01
modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticated users to create or modify user accounts via unspecified vectors.
- CVE-2017-17976Jan 26, 2018risk 0.04cvss —epss 0.17
In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.
- CVE-2014-10009Jan 13, 2015risk 0.03cvss —epss 0.03
Multiple cross-site scripting (XSS) vulnerabilities in Stark CRM 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, or (3) notes parameter to the client page; (4) insu_name or (5) price parameter to the add_insurance_cat…
- CVE-2013-3213Apr 2, 2014risk 0.03cvss —epss 0.00
Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) picklist_name parameter in the get_picklists method to soap/customerportal.php, (2) where parameter in the get_tickets_list method to…
- CVE-2024-8867Sep 15, 2024risk 0.00cvss —epss 0.00
A vulnerability was found in Perfex CRM 3.1.6. It has been declared as problematic. This vulnerability affects unknown code of the file application/controllers/Clients.php of the component Parameter Handler. The manipulation of the argument message leads to cross site scripting.…