Перейти к содержимому
Noroxi

Записи Vtiger

72 опубликованных записей вендора vtiger.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
6 · 8,3 %
Pre-auth RCE
13
С записью об исправлении
1,4 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

72 записей
  • CVE-2013-3214
    64На этой неделе

    vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 85 %

    vtiger · vtiger crm28 янв. 2020 г.

  • CVE-2013-3215
    60На этой неделе

    vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession

    КритическаяCVSS 9,8Готовый эксплойтEPSS 69 %

    vtiger · vtiger crm29 янв. 2020 г.

  • CVE-2013-3591
    48В плане

    vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 43 %

    vtiger · vtiger crm7 февр. 2020 г.

  • CVE-2015-6000
    47В плане

    Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDeta

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 40 %

    vtiger · vtiger crm6 февр. 2020 г.

  • CVE-2009-3250
    39Наблюдать

    The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbi

    КритическаяCVSS 9,0Proof of conceptEPSS 11 %

    vtiger · vtiger crm18 сент. 2009 г.

  • CVE-2020-22807
    39Наблюдать

    An issue was dicovered in vtiger crm 7.2.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    vtiger · vtiger crm29 апр. 2021 г.

  • CVE-2024-44779
    38Наблюдать

    A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to exe

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    vtiger · vtiger crm29 авг. 2024 г.

  • CVE-2024-44778
    38Наблюдать

    A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execu

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    vtiger · vtiger crm29 авг. 2024 г.

  • CVE-2024-44777
    38Наблюдать

    A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    vtiger · vtiger crm29 авг. 2024 г.

  • CVE-2009-3258
    37Наблюдать

    vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filters

    КритическаяCVSS 9,0Эксплойта нетEPSS 2 %

    vtiger · vtiger crm18 сент. 2009 г.

  • CVE-2016-10754
    35Наблюдать

    modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    vtiger · vtiger crm24 мая 2019 г.

  • CVE-2023-38891
    35Наблюдать

    SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList

    ВысокаяCVSS 8,8Proof of conceptEPSS 1 %

    vtiger · vtiger crm14 сент. 2023 г.

  • CVE-2019-11057
    35Наблюдать

    SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    vtiger · vtiger crm17 мая 2019 г.

  • CVE-2019-19202
    35Наблюдать

    In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role b

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    vtiger · vtiger crm21 нояб. 2019 г.

  • CVE-2016-1713
    34Наблюдать

    Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDeta

    ВысокаяCVSS 7,3Готовый эксплойтEPSS 17 %

    vtiger · vtiger crm14 апр. 2017 г.

  • CVE-2013-3212
    34Наблюдать

    vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files

    ВысокаяCVSS 8,1Proof of conceptEPSS 8 %

    vtiger · vtiger crm28 янв. 2020 г.

  • CVE-2007-3599
    34Наблюдать

    vtiger CRM before 5.0.3 allows remote authenticated users to import and export the information for a contact even when they only have the Vi

    ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %

    vtiger · vtiger crm6 июл. 2007 г.

  • CVE-2009-3249
    33Наблюдать

    Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .

    ВысокаяCVSS 7,5Proof of conceptEPSS 10 %

    vtiger · vtiger crm18 сент. 2009 г.

  • CVE-2016-4834
    33Наблюдать

    modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticat

    ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %

    vtiger · vtiger crm31 июл. 2016 г.

  • CVE-2024-42995
    33Наблюдать

    VTiger CRM <= 8.1.0 does not correctly check user privileges.

    ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %

    vtiger · vtiger crm16 авг. 2024 г.

  • CVE-2006-5289
    32Наблюдать

    Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a

    ВысокаяCVSS 7,5Proof of conceptEPSS 8 %

    vtiger · vtiger crm13 окт. 2006 г.

  • CVE-2023-46304
    32Наблюдать

    modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected

    ВысокаяCVSS 8,1Proof of conceptEPSS 2 %

    vtiger · vtiger crm30 апр. 2024 г.

  • CVE-2019-5009
    31Наблюдать

    Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG fo

    ВысокаяCVSS 7,2Proof of conceptEPSS 10 %

    vtiger · vtiger crm4 янв. 2019 г.

  • CVE-2013-3213
    31Наблюдать

    Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    vtiger · vtiger crm2 апр. 2014 г.

  • CVE-2005-3819
    31Наблюдать

    Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass auth

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    vtiger · vtiger crm25 нояб. 2005 г.