Записи Vtiger
72 опубликованных записей вендора vtiger.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 6 · 8,3 %
- Pre-auth RCE
- 13
- С записью об исправлении
- 1,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')16
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-264 Permissions, Privileges, and Access Controls6
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
72 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2013-3214Готовый эксплойт | vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.vtiger · vtiger crm · CWE-74 | Критическая9,8 | — | 84,5 % | 28 янв. 2020 г. |
60На этой неделе | CVE-2013-3215Готовый эксплойт | vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSessionvtiger · vtiger crm · CWE-287 | Критическая9,8 | — | 68,8 % | 29 янв. 2020 г. |
48В плане | CVE-2013-3591Готовый эксплойт | vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerabilityvtiger · vtiger crm · CWE-434 | Высокая8,8 | — | 43,1 % | 7 февр. 2020 г. |
47В плане | CVE-2015-6000Готовый эксплойт | Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetavtiger · vtiger crm · CWE-434 | Высокая8,8 | — | 40,2 % | 6 февр. 2020 г. |
39Наблюдать | CVE-2009-3250Proof of concept | The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbivtiger · vtiger crm · CWE-20 | Критическая9,0 | — | 10,9 % | 18 сент. 2009 г. |
39Наблюдать | CVE-2020-22807Эксплойта нет | An issue was dicovered in vtiger crm 7.2.vtiger · vtiger crm · CWE-89 | Критическая9,8 | — | 1,3 % | 29 апр. 2021 г. |
38Наблюдать | CVE-2024-44779Эксплойта нет | A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to exevtiger · vtiger crm · CWE-79 | Критическая9,6 | — | 0,8 % | 29 авг. 2024 г. |
38Наблюдать | CVE-2024-44778Эксплойта нет | A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execuvtiger · vtiger crm · CWE-79 | Критическая9,6 | — | 0,7 % | 29 авг. 2024 г. |
38Наблюдать | CVE-2024-44777Эксплойта нет | A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute vtiger · vtiger crm · CWE-79 | Критическая9,6 | — | 0,7 % | 29 авг. 2024 г. |
37Наблюдать | CVE-2009-3258Эксплойта нет | vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filtersvtiger · vtiger crm · CWE-264 | Критическая9,0 | — | 1,7 % | 18 сент. 2009 г. |
35Наблюдать | CVE-2016-10754Эксплойта нет | modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.vtiger · vtiger crm · CWE-89 | Высокая8,8 | — | 1,4 % | 24 мая 2019 г. |
35Наблюдать | CVE-2023-38891Proof of concept | SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList vtiger · vtiger crm · CWE-89 | Высокая8,8 | — | 1,3 % | 14 сент. 2023 г. |
35Наблюдать | CVE-2019-11057Эксплойта нет | SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.vtiger · vtiger crm · CWE-89 | Высокая8,8 | — | 1,2 % | 17 мая 2019 г. |
35Наблюдать | CVE-2019-19202Эксплойта нет | In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role bvtiger · vtiger crm · CWE-276 | Высокая8,8 | — | 1,0 % | 21 нояб. 2019 г. |
34Наблюдать | CVE-2016-1713Готовый эксплойт | Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetavtiger · vtiger crm · CWE-434 | Высокая7,3 | — | 16,6 % | 14 апр. 2017 г. |
34Наблюдать | CVE-2013-3212Proof of concept | vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files vtiger · vtiger crm · CWE-74 | Высокая8,1 | — | 7,5 % | 28 янв. 2020 г. |
34Наблюдать | CVE-2007-3599Эксплойта нет | vtiger CRM before 5.0.3 allows remote authenticated users to import and export the information for a contact even when they only have the Vivtiger · vtiger crm | Высокая8,5 | — | 1,3 % | 6 июл. 2007 г. |
33Наблюдать | CVE-2009-3249Proof of concept | Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .vtiger · vtiger crm · CWE-22 | Высокая7,5 | — | 9,6 % | 18 сент. 2009 г. |
33Наблюдать | CVE-2016-4834Эксплойта нет | modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticatvtiger · vtiger crm · CWE-264 | Высокая8,1 | — | 2,2 % | 31 июл. 2016 г. |
33Наблюдать | CVE-2024-42995Эксплойта нет | VTiger CRM <= 8.1.0 does not correctly check user privileges.vtiger · vtiger crm · CWE-269 | Высокая8,3 | — | 0,4 % | 16 авг. 2024 г. |
32Наблюдать | CVE-2006-5289Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a vtiger · vtiger crm | Высокая7,5 | — | 7,9 % | 13 окт. 2006 г. |
32Наблюдать | CVE-2023-46304Proof of concept | modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected vtiger · vtiger crm · CWE-74 | Высокая8,1 | — | 1,7 % | 30 апр. 2024 г. |
31Наблюдать | CVE-2019-5009Proof of concept | Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG fovtiger · vtiger crm · CWE-434 | Высокая7,2 | — | 9,9 % | 4 янв. 2019 г. |
31Наблюдать | CVE-2013-3213Proof of concept | Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1vtiger · vtiger crm · CWE-89 | Высокая7,5 | — | 3,1 % | 2 апр. 2014 г. |
31Наблюдать | CVE-2005-3819Proof of concept | Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass authvtiger · vtiger crm | Высокая7,5 | — | 2,8 % | 25 нояб. 2005 г. |
- CVE-2013-321464На этой неделе
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
КритическаяCVSS 9,8Готовый эксплойтEPSS 85 %vtiger · vtiger crm28 янв. 2020 г.
- CVE-2013-321560На этой неделе
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession
КритическаяCVSS 9,8Готовый эксплойтEPSS 69 %vtiger · vtiger crm29 янв. 2020 г.
- CVE-2013-359148В плане
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
ВысокаяCVSS 8,8Готовый эксплойтEPSS 43 %vtiger · vtiger crm7 февр. 2020 г.
- CVE-2015-600047В плане
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDeta
ВысокаяCVSS 8,8Готовый эксплойтEPSS 40 %vtiger · vtiger crm6 февр. 2020 г.
- CVE-2009-325039Наблюдать
The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbi
КритическаяCVSS 9,0Proof of conceptEPSS 11 %vtiger · vtiger crm18 сент. 2009 г.
- CVE-2020-2280739Наблюдать
An issue was dicovered in vtiger crm 7.2.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %vtiger · vtiger crm29 апр. 2021 г.
- CVE-2024-4477938Наблюдать
A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to exe
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %vtiger · vtiger crm29 авг. 2024 г.
- CVE-2024-4477838Наблюдать
A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execu
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %vtiger · vtiger crm29 авг. 2024 г.
- CVE-2024-4477738Наблюдать
A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %vtiger · vtiger crm29 авг. 2024 г.
- CVE-2009-325837Наблюдать
vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filters
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %vtiger · vtiger crm18 сент. 2009 г.
- CVE-2016-1075435Наблюдать
modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %vtiger · vtiger crm24 мая 2019 г.
- CVE-2023-3889135Наблюдать
SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %vtiger · vtiger crm14 сент. 2023 г.
- CVE-2019-1105735Наблюдать
SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %vtiger · vtiger crm17 мая 2019 г.
- CVE-2019-1920235Наблюдать
In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role b
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %vtiger · vtiger crm21 нояб. 2019 г.
- CVE-2016-171334Наблюдать
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDeta
ВысокаяCVSS 7,3Готовый эксплойтEPSS 17 %vtiger · vtiger crm14 апр. 2017 г.
- CVE-2013-321234Наблюдать
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files
ВысокаяCVSS 8,1Proof of conceptEPSS 8 %vtiger · vtiger crm28 янв. 2020 г.
- CVE-2007-359934Наблюдать
vtiger CRM before 5.0.3 allows remote authenticated users to import and export the information for a contact even when they only have the Vi
ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %vtiger · vtiger crm6 июл. 2007 г.
- CVE-2009-324933Наблюдать
Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .
ВысокаяCVSS 7,5Proof of conceptEPSS 10 %vtiger · vtiger crm18 сент. 2009 г.
- CVE-2016-483433Наблюдать
modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticat
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %vtiger · vtiger crm31 июл. 2016 г.
- CVE-2024-4299533Наблюдать
VTiger CRM <= 8.1.0 does not correctly check user privileges.
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %vtiger · vtiger crm16 авг. 2024 г.
- CVE-2006-528932Наблюдать
Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %vtiger · vtiger crm13 окт. 2006 г.
- CVE-2023-4630432Наблюдать
modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected
ВысокаяCVSS 8,1Proof of conceptEPSS 2 %vtiger · vtiger crm30 апр. 2024 г.
- CVE-2019-500931Наблюдать
Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG fo
ВысокаяCVSS 7,2Proof of conceptEPSS 10 %vtiger · vtiger crm4 янв. 2019 г.
- CVE-2013-321331Наблюдать
Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %vtiger · vtiger crm2 апр. 2014 г.
- CVE-2005-381931Наблюдать
Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass auth
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %vtiger · vtiger crm25 нояб. 2005 г.