zurmo records
9 published records for vendor zurmo.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
24Monitor | CVE-2019-14472No exploit | Zurmo 3.2.7-2 has XSS via the app/index.php/zurmo/default PATH_INFO.zurmo · zurmo · CWE-79 | Medium6.1 | — | 0.8% | Aug 1, 2019 |
24Monitor | CVE-2018-16654No exploit | Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1.zurmo · zurmo crm · CWE-79 | Medium6.1 | — | 0.8% | Sep 7, 2018 |
21Monitor | CVE-2017-7188Proof of concept | Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl paramzurmo · zurmo crm · CWE-79 | Medium5.4 | — | 1.4% | Apr 14, 2017 |
21Monitor | CVE-2017-18004No exploit | Zurmo 3.2.3 allows XSS via the latitude or longitude parameter to maps/default/mapAndPoint.zurmo · zurmo crm · CWE-79 | Medium5.4 | — | 0.6% | Dec 31, 2017 |
19Monitor | CVE-2018-19596No exploit | Zurmo 3.2.4 allows HTML Injection via an admin's use of HTML in the report section, a related issue to CVE-2018-19506.zurmo · zurmo · CWE-79 | Medium4.8 | — | 0.6% | Dec 19, 2018 |
19Monitor | CVE-2018-19506No exploit | Zurmo 3.2.4 has XSS via an admin's use of the name parameter in the reports section, aka the app/index.php/reports/default/details?id=1 URI.zurmo · zurmo · CWE-79 | Medium4.8 | — | 0.6% | Dec 19, 2018 |
19Monitor | CVE-2017-16569No exploit | An Open URL Redirect issue exists in Zurmo 3.2.1.57987acc3018 via an http: URL in the redirectUrl parameter to app/index.php/meetings/defaulzurmo · zurmo crm · CWE-601 | Medium4.8 | — | 0.5% | Nov 6, 2017 |
19Monitor | CVE-2017-15039No exploit | Cross-site scripting (XSS) exists in Zurmo 3.2.1.57987acc3018 via a data: URL in the redirectUrl parameter to app/index.php/meetings/defaultzurmo · zurmo crm · CWE-79 | Medium4.8 | — | 0.5% | Nov 6, 2017 |
14Monitor | CVE-2015-5365No exploit | Cross-site scripting (XSS) vulnerability in Zurmo CRM 3.0.2 allows remote authenticated users to inject arbitrary web script or HTML via thezurmo · zurmo crm · CWE-79 | Low3.5 | — | 1.1% | Jul 2, 2015 |
- CVE-2019-1447224Monitor
Zurmo 3.2.7-2 has XSS via the app/index.php/zurmo/default PATH_INFO.
MediumCVSS 6.1No exploitEPSS 1%zurmo · zurmoAug 1, 2019
- CVE-2018-1665424Monitor
Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1.
MediumCVSS 6.1No exploitEPSS 1%zurmo · zurmo crmSep 7, 2018
- CVE-2017-718821Monitor
Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl param
MediumCVSS 5.4Proof of conceptEPSS 1%zurmo · zurmo crmApr 14, 2017
- CVE-2017-1800421Monitor
Zurmo 3.2.3 allows XSS via the latitude or longitude parameter to maps/default/mapAndPoint.
MediumCVSS 5.4No exploitEPSS 1%zurmo · zurmo crmDec 31, 2017
- CVE-2018-1959619Monitor
Zurmo 3.2.4 allows HTML Injection via an admin's use of HTML in the report section, a related issue to CVE-2018-19506.
MediumCVSS 4.8No exploitEPSS 1%zurmo · zurmoDec 19, 2018
- CVE-2018-1950619Monitor
Zurmo 3.2.4 has XSS via an admin's use of the name parameter in the reports section, aka the app/index.php/reports/default/details?id=1 URI.
MediumCVSS 4.8No exploitEPSS 1%zurmo · zurmoDec 19, 2018
- CVE-2017-1656919Monitor
An Open URL Redirect issue exists in Zurmo 3.2.1.57987acc3018 via an http: URL in the redirectUrl parameter to app/index.php/meetings/defaul
MediumCVSS 4.8No exploitEPSS 0%zurmo · zurmo crmNov 6, 2017
- CVE-2017-1503919Monitor
Cross-site scripting (XSS) exists in Zurmo 3.2.1.57987acc3018 via a data: URL in the redirectUrl parameter to app/index.php/meetings/default
MediumCVSS 4.8No exploitEPSS 0%zurmo · zurmo crmNov 6, 2017
- CVE-2015-536514Monitor
Cross-site scripting (XSS) vulnerability in Zurmo CRM 3.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the
LowCVSS 3.5No exploitEPSS 1%zurmo · zurmo crmJul 2, 2015