Записи x2engine
15 опубликованных записей вендора x2engine.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-20 Improper Input Validation1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2013-5692Proof of concept | Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary lx2engine · x2crm · CWE-22 | Высокая8,5 | — | 5,8 % | 30 сент. 2013 г. |
36Наблюдать | CVE-2014-2664Эксплойта нет | Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/ProfileController.php in x2engine · x2crm · CWE-434 | Высокая8,8 | — | 2,9 % | 17 окт. 2017 г. |
32Наблюдать | CVE-2015-5074Proof of concept | Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM bex2engine · x2crm · CWE-20 | Высокая7,5 | — | 7,5 % | 29 сент. 2015 г. |
31Наблюдать | CVE-2014-5297Эксплойта нет | The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 through 4.1.7 allows remote attackers to conducx2engine · x2engine · CWE-94 | Высокая7,5 | — | 2,7 % | 9 окт. 2014 г. |
28Наблюдать | CVE-2015-5075Proof of concept | Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of adminisx2engine · x2crm · CWE-352 | Средняя6,8 | — | 2,8 % | 29 сент. 2015 г. |
24Наблюдать | CVE-2020-21087Эксплойта нет | Cross Site Scripting (XSS) in X2Engine X2CRM v6.9 and older allows remote attackers to execute arbitrary code by injecting arbitrary web scrx2engine · x2crm · CWE-79 | Средняя6,1 | — | 1,4 % | 14 апр. 2021 г. |
24Наблюдать | CVE-2021-27288Эксплойта нет | Cross Site Scripting (XSS) in X2Engine X2CRM v7.1 allows remote attackers to obtain sensitive information by injecting arbitrary web script x2engine · x2crm · CWE-79 | Средняя6,1 | — | 0,9 % | 14 апр. 2021 г. |
22Наблюдать | CVE-2022-48178Proof of concept | X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action fux2engine · x2crm · CWE-79 | Средняя5,4 | — | 1,8 % | 14 апр. 2023 г. |
22Наблюдать | CVE-2022-48177Proof of concept | X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importMox2engine · x2crm · CWE-79 | Средняя5,4 | — | 1,8 % | 14 апр. 2023 г. |
21Наблюдать | CVE-2014-5298Эксплойта нет | FileUploadsFilter.php in X2Engine 4.1.7 and earlier, when running on case-insensitive file systems, allows remote attackers to bypass the upx2engine · x2engine · CWE-264 | Средняя5,0 | — | 3,0 % | 9 окт. 2014 г. |
21Наблюдать | CVE-2024-48120Proof of concept | X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module.x2engine · x2crm · CWE-79 | Средняя5,4 | — | 0,7 % | 14 окт. 2024 г. |
21Наблюдать | CVE-2021-33853Эксплойта нет | A Cross-Site Scripting (XSS) attack can cause arbitrary code (javascript) to run in a user’s browser while the browser is connected to a trux2engine · x2crm · CWE-79 | Средняя5,4 | — | 0,6 % | 16 мар. 2022 г. |
19Наблюдать | CVE-2020-21088Эксплойта нет | Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by injecting arbitrary wx2engine · x2crm · CWE-79 | Средняя4,8 | — | 0,8 % | 14 апр. 2021 г. |
18Наблюдать | CVE-2013-5693Proof of concept | Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web script or HTML via thex2engine · x2crm · CWE-79 | Средняя4,3 | — | 3,2 % | 30 сент. 2013 г. |
18Наблюдать | CVE-2015-5076Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in X2Engine X2CRM before 5.0.9 allow remote attackers to inject arbitrary web script or x2engine · x2crm · CWE-79 | Средняя4,3 | — | 1,9 % | 29 сент. 2015 г. |
- CVE-2013-569236Наблюдать
Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary l
ВысокаяCVSS 8,5Proof of conceptEPSS 6 %x2engine · x2crm30 сент. 2013 г.
- CVE-2014-266436Наблюдать
Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/ProfileController.php in
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %x2engine · x2crm17 окт. 2017 г.
- CVE-2015-507432Наблюдать
Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM be
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %x2engine · x2crm29 сент. 2015 г.
- CVE-2014-529731Наблюдать
The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 through 4.1.7 allows remote attackers to conduc
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %x2engine · x2engine9 окт. 2014 г.
- CVE-2015-507528Наблюдать
Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of adminis
СредняяCVSS 6,8Proof of conceptEPSS 3 %x2engine · x2crm29 сент. 2015 г.
- CVE-2020-2108724Наблюдать
Cross Site Scripting (XSS) in X2Engine X2CRM v6.9 and older allows remote attackers to execute arbitrary code by injecting arbitrary web scr
СредняяCVSS 6,1Эксплойта нетEPSS 1 %x2engine · x2crm14 апр. 2021 г.
- CVE-2021-2728824Наблюдать
Cross Site Scripting (XSS) in X2Engine X2CRM v7.1 allows remote attackers to obtain sensitive information by injecting arbitrary web script
СредняяCVSS 6,1Эксплойта нетEPSS 1 %x2engine · x2crm14 апр. 2021 г.
- CVE-2022-4817822Наблюдать
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action fu
СредняяCVSS 5,4Proof of conceptEPSS 2 %x2engine · x2crm14 апр. 2023 г.
- CVE-2022-4817722Наблюдать
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importMo
СредняяCVSS 5,4Proof of conceptEPSS 2 %x2engine · x2crm14 апр. 2023 г.
- CVE-2014-529821Наблюдать
FileUploadsFilter.php in X2Engine 4.1.7 and earlier, when running on case-insensitive file systems, allows remote attackers to bypass the up
СредняяCVSS 5,0Эксплойта нетEPSS 3 %x2engine · x2engine9 окт. 2014 г.
- CVE-2024-4812021Наблюдать
X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module.
СредняяCVSS 5,4Proof of conceptEPSS 1 %x2engine · x2crm14 окт. 2024 г.
- CVE-2021-3385321Наблюдать
A Cross-Site Scripting (XSS) attack can cause arbitrary code (javascript) to run in a user’s browser while the browser is connected to a tru
СредняяCVSS 5,4Эксплойта нетEPSS 1 %x2engine · x2crm16 мар. 2022 г.
- CVE-2020-2108819Наблюдать
Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by injecting arbitrary w
СредняяCVSS 4,8Эксплойта нетEPSS 1 %x2engine · x2crm14 апр. 2021 г.
- CVE-2013-569318Наблюдать
Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web script or HTML via the
СредняяCVSS 4,3Proof of conceptEPSS 3 %x2engine · x2crm30 сент. 2013 г.
- CVE-2015-507618Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in X2Engine X2CRM before 5.0.9 allow remote attackers to inject arbitrary web script or
СредняяCVSS 4,3Эксплойта нетEPSS 2 %x2engine · x2crm29 сент. 2015 г.