VYPR
Vendor

Zurmo

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2017-7188MedApr 14, 2017
    risk 0.35cvss 5.4epss 0.01

    Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse.

  • CVE-2017-16569MedNov 6, 2017
    risk 0.31cvss 4.8epss 0.00

    An Open URL Redirect issue exists in Zurmo 3.2.1.57987acc3018 via an http: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting.

  • CVE-2015-5365Jul 2, 2015
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in Zurmo CRM 3.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "What's going on?" profile field.