Записи dimo-crm
4 опубликованных записей вендора dimo-crm.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2019-14768Эксплойта нет | An Arbitrary File Upload issue in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to deploy a new Wdimo-crm · yellowbox crm · CWE-22 | Высокая8,8 | — | 4,3 % | 21 янв. 2020 г. |
35Наблюдать | CVE-2019-14765Эксплойта нет | Incorrect Access Control in AfficheExplorateurParam() in DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to use adminisdimo-crm · yellowbox crm | Высокая8,8 | — | 1,1 % | 21 янв. 2020 г. |
30Наблюдать | CVE-2019-14767Эксплойта нет | In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an unadimo-crm · yellowbox crm · CWE-22 | Высокая7,5 | — | 1,4 % | 21 янв. 2020 г. |
26Наблюдать | CVE-2019-14766Эксплойта нет | Path Traversal in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to browse the server filesystem.dimo-crm · yellowbox crm · CWE-22 | Средняя6,5 | — | 1,1 % | 21 янв. 2020 г. |
- CVE-2019-1476836Наблюдать
An Arbitrary File Upload issue in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to deploy a new W
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %dimo-crm · yellowbox crm21 янв. 2020 г.
- CVE-2019-1476535Наблюдать
Incorrect Access Control in AfficheExplorateurParam() in DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to use adminis
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %dimo-crm · yellowbox crm21 янв. 2020 г.
- CVE-2019-1476730Наблюдать
In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an una
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dimo-crm · yellowbox crm21 янв. 2020 г.
- CVE-2019-1476626Наблюдать
Path Traversal in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to browse the server filesystem.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %dimo-crm · yellowbox crm21 янв. 2020 г.