Vtiger kayıtları
vtiger üreticisine ait 72 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 6 · %8,3
- Pre-auth RCE
- 13
- Düzeltme kaydı olan
- %1,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')16
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-264 Permissions, Privileges, and Access Controls6
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
72 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
64Bu hafta | CVE-2013-3214Silahlaştırılmış | vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.vtiger · vtiger crm · CWE-74 | Kritik9,8 | — | %84,5 | 28 Oca 2020 |
60Bu hafta | CVE-2013-3215Silahlaştırılmış | vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSessionvtiger · vtiger crm · CWE-287 | Kritik9,8 | — | %68,8 | 29 Oca 2020 |
48Planlayın | CVE-2013-3591Silahlaştırılmış | vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerabilityvtiger · vtiger crm · CWE-434 | Yüksek8,8 | — | %43,1 | 7 Şub 2020 |
47Planlayın | CVE-2015-6000Silahlaştırılmış | Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetavtiger · vtiger crm · CWE-434 | Yüksek8,8 | — | %40,2 | 6 Şub 2020 |
39İzleyin | CVE-2009-3250Kavram kanıtı | The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbivtiger · vtiger crm · CWE-20 | Kritik9,0 | — | %10,9 | 18 Eyl 2009 |
39İzleyin | CVE-2020-22807İstismar yok | An issue was dicovered in vtiger crm 7.2.vtiger · vtiger crm · CWE-89 | Kritik9,8 | — | %1,3 | 29 Nis 2021 |
38İzleyin | CVE-2024-44779İstismar yok | A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to exevtiger · vtiger crm · CWE-79 | Kritik9,6 | — | %0,8 | 29 Ağu 2024 |
38İzleyin | CVE-2024-44778İstismar yok | A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execuvtiger · vtiger crm · CWE-79 | Kritik9,6 | — | %0,7 | 29 Ağu 2024 |
38İzleyin | CVE-2024-44777İstismar yok | A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute vtiger · vtiger crm · CWE-79 | Kritik9,6 | — | %0,7 | 29 Ağu 2024 |
37İzleyin | CVE-2009-3258İstismar yok | vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filtersvtiger · vtiger crm · CWE-264 | Kritik9,0 | — | %1,7 | 18 Eyl 2009 |
35İzleyin | CVE-2016-10754İstismar yok | modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.vtiger · vtiger crm · CWE-89 | Yüksek8,8 | — | %1,4 | 24 May 2019 |
35İzleyin | CVE-2023-38891Kavram kanıtı | SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList vtiger · vtiger crm · CWE-89 | Yüksek8,8 | — | %1,3 | 14 Eyl 2023 |
35İzleyin | CVE-2019-11057İstismar yok | SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.vtiger · vtiger crm · CWE-89 | Yüksek8,8 | — | %1,2 | 17 May 2019 |
35İzleyin | CVE-2019-19202İstismar yok | In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role bvtiger · vtiger crm · CWE-276 | Yüksek8,8 | — | %1,0 | 21 Kas 2019 |
34İzleyin | CVE-2016-1713Silahlaştırılmış | Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetavtiger · vtiger crm · CWE-434 | Yüksek7,3 | — | %16,6 | 14 Nis 2017 |
34İzleyin | CVE-2013-3212Kavram kanıtı | vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files vtiger · vtiger crm · CWE-74 | Yüksek8,1 | — | %7,5 | 28 Oca 2020 |
34İzleyin | CVE-2007-3599İstismar yok | vtiger CRM before 5.0.3 allows remote authenticated users to import and export the information for a contact even when they only have the Vivtiger · vtiger crm | Yüksek8,5 | — | %1,3 | 6 Tem 2007 |
33İzleyin | CVE-2009-3249Kavram kanıtı | Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .vtiger · vtiger crm · CWE-22 | Yüksek7,5 | — | %9,6 | 18 Eyl 2009 |
33İzleyin | CVE-2016-4834İstismar yok | modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticatvtiger · vtiger crm · CWE-264 | Yüksek8,1 | — | %2,2 | 31 Tem 2016 |
33İzleyin | CVE-2024-42995İstismar yok | VTiger CRM <= 8.1.0 does not correctly check user privileges.vtiger · vtiger crm · CWE-269 | Yüksek8,3 | — | %0,4 | 16 Ağu 2024 |
32İzleyin | CVE-2006-5289Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a vtiger · vtiger crm | Yüksek7,5 | — | %7,9 | 13 Eki 2006 |
32İzleyin | CVE-2023-46304Kavram kanıtı | modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected vtiger · vtiger crm · CWE-74 | Yüksek8,1 | — | %1,7 | 30 Nis 2024 |
31İzleyin | CVE-2019-5009Kavram kanıtı | Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG fovtiger · vtiger crm · CWE-434 | Yüksek7,2 | — | %9,9 | 4 Oca 2019 |
31İzleyin | CVE-2013-3213Kavram kanıtı | Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1vtiger · vtiger crm · CWE-89 | Yüksek7,5 | — | %3,1 | 2 Nis 2014 |
31İzleyin | CVE-2005-3819Kavram kanıtı | Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass authvtiger · vtiger crm | Yüksek7,5 | — | %2,8 | 25 Kas 2005 |
- CVE-2013-321464Bu hafta
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
KritikCVSS 9,8SilahlaştırılmışEPSS %85vtiger · vtiger crm28 Oca 2020
- CVE-2013-321560Bu hafta
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession
KritikCVSS 9,8SilahlaştırılmışEPSS %69vtiger · vtiger crm29 Oca 2020
- CVE-2013-359148Planlayın
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
YüksekCVSS 8,8SilahlaştırılmışEPSS %43vtiger · vtiger crm7 Şub 2020
- CVE-2015-600047Planlayın
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDeta
YüksekCVSS 8,8SilahlaştırılmışEPSS %40vtiger · vtiger crm6 Şub 2020
- CVE-2009-325039İzleyin
The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbi
KritikCVSS 9,0Kavram kanıtıEPSS %11vtiger · vtiger crm18 Eyl 2009
- CVE-2020-2280739İzleyin
An issue was dicovered in vtiger crm 7.2.
KritikCVSS 9,8İstismar yokEPSS %1vtiger · vtiger crm29 Nis 2021
- CVE-2024-4477938İzleyin
A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to exe
KritikCVSS 9,6İstismar yokEPSS %1vtiger · vtiger crm29 Ağu 2024
- CVE-2024-4477838İzleyin
A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execu
KritikCVSS 9,6İstismar yokEPSS %1vtiger · vtiger crm29 Ağu 2024
- CVE-2024-4477738İzleyin
A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute
KritikCVSS 9,6İstismar yokEPSS %1vtiger · vtiger crm29 Ağu 2024
- CVE-2009-325837İzleyin
vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filters
KritikCVSS 9,0İstismar yokEPSS %2vtiger · vtiger crm18 Eyl 2009
- CVE-2016-1075435İzleyin
modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.
YüksekCVSS 8,8İstismar yokEPSS %1vtiger · vtiger crm24 May 2019
- CVE-2023-3889135İzleyin
SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList
YüksekCVSS 8,8Kavram kanıtıEPSS %1vtiger · vtiger crm14 Eyl 2023
- CVE-2019-1105735İzleyin
SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.
YüksekCVSS 8,8İstismar yokEPSS %1vtiger · vtiger crm17 May 2019
- CVE-2019-1920235İzleyin
In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role b
YüksekCVSS 8,8İstismar yokEPSS %1vtiger · vtiger crm21 Kas 2019
- CVE-2016-171334İzleyin
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDeta
YüksekCVSS 7,3SilahlaştırılmışEPSS %17vtiger · vtiger crm14 Nis 2017
- CVE-2013-321234İzleyin
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files
YüksekCVSS 8,1Kavram kanıtıEPSS %8vtiger · vtiger crm28 Oca 2020
- CVE-2007-359934İzleyin
vtiger CRM before 5.0.3 allows remote authenticated users to import and export the information for a contact even when they only have the Vi
YüksekCVSS 8,5İstismar yokEPSS %1vtiger · vtiger crm6 Tem 2007
- CVE-2009-324933İzleyin
Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .
YüksekCVSS 7,5Kavram kanıtıEPSS %10vtiger · vtiger crm18 Eyl 2009
- CVE-2016-483433İzleyin
modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticat
YüksekCVSS 8,1İstismar yokEPSS %2vtiger · vtiger crm31 Tem 2016
- CVE-2024-4299533İzleyin
VTiger CRM <= 8.1.0 does not correctly check user privileges.
YüksekCVSS 8,3İstismar yokEPSS %0vtiger · vtiger crm16 Ağu 2024
- CVE-2006-528932İzleyin
Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a
YüksekCVSS 7,5Kavram kanıtıEPSS %8vtiger · vtiger crm13 Eki 2006
- CVE-2023-4630432İzleyin
modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected
YüksekCVSS 8,1Kavram kanıtıEPSS %2vtiger · vtiger crm30 Nis 2024
- CVE-2019-500931İzleyin
Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG fo
YüksekCVSS 7,2Kavram kanıtıEPSS %10vtiger · vtiger crm4 Oca 2019
- CVE-2013-321331İzleyin
Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1
YüksekCVSS 7,5Kavram kanıtıEPSS %3vtiger · vtiger crm2 Nis 2014
- CVE-2005-381931İzleyin
Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass auth
YüksekCVSS 7,5Kavram kanıtıEPSS %3vtiger · vtiger crm25 Kas 2005