VYPR

vTiger

by Vtiger

CVEs (44)

  • CVE-2007-3617Jul 6, 2007
    risk 0.00cvss —epss 0.01

    The report module in vtiger CRM before 5.0.3 does not properly apply security rules, which allows remote authenticated users to read arbitrary private module entries.

  • CVE-2007-3604Jul 6, 2007
    risk 0.00cvss —epss 0.01

    vtiger CRM before 5.0.3 allows remote authenticated users with access to the Analytics DashBoard menu to bypass data restrictions and read the pipeline of the entire organization, possibly involving modules/Potentials/Potentials.php.

  • CVE-2005-3823Nov 26, 2005
    risk 0.00cvss —epss 0.02

    The Users module in vTiger CRM 4.2 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary file in the templatename parameter, which is passed to the eval function.

  • CVE-2005-3824Nov 26, 2005
    risk 0.00cvss —epss 0.01

    The uploads module in vTiger CRM 4.2 and earlier allows remote attackers to upload arbitrary files, such as PHP files, via the add2db action.

Page 3 of 3