zurmo kayıtları
zurmo üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
24İzleyin | CVE-2019-14472İstismar yok | Zurmo 3.2.7-2 has XSS via the app/index.php/zurmo/default PATH_INFO.zurmo · zurmo · CWE-79 | Orta6,1 | — | %0,8 | 1 Ağu 2019 |
24İzleyin | CVE-2018-16654İstismar yok | Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1.zurmo · zurmo crm · CWE-79 | Orta6,1 | — | %0,8 | 7 Eyl 2018 |
21İzleyin | CVE-2017-7188Kavram kanıtı | Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl paramzurmo · zurmo crm · CWE-79 | Orta5,4 | — | %1,4 | 14 Nis 2017 |
21İzleyin | CVE-2017-18004İstismar yok | Zurmo 3.2.3 allows XSS via the latitude or longitude parameter to maps/default/mapAndPoint.zurmo · zurmo crm · CWE-79 | Orta5,4 | — | %0,6 | 31 Ara 2017 |
19İzleyin | CVE-2018-19596İstismar yok | Zurmo 3.2.4 allows HTML Injection via an admin's use of HTML in the report section, a related issue to CVE-2018-19506.zurmo · zurmo · CWE-79 | Orta4,8 | — | %0,6 | 19 Ara 2018 |
19İzleyin | CVE-2018-19506İstismar yok | Zurmo 3.2.4 has XSS via an admin's use of the name parameter in the reports section, aka the app/index.php/reports/default/details?id=1 URI.zurmo · zurmo · CWE-79 | Orta4,8 | — | %0,6 | 19 Ara 2018 |
19İzleyin | CVE-2017-16569İstismar yok | An Open URL Redirect issue exists in Zurmo 3.2.1.57987acc3018 via an http: URL in the redirectUrl parameter to app/index.php/meetings/defaulzurmo · zurmo crm · CWE-601 | Orta4,8 | — | %0,5 | 6 Kas 2017 |
19İzleyin | CVE-2017-15039İstismar yok | Cross-site scripting (XSS) exists in Zurmo 3.2.1.57987acc3018 via a data: URL in the redirectUrl parameter to app/index.php/meetings/defaultzurmo · zurmo crm · CWE-79 | Orta4,8 | — | %0,5 | 6 Kas 2017 |
14İzleyin | CVE-2015-5365İstismar yok | Cross-site scripting (XSS) vulnerability in Zurmo CRM 3.0.2 allows remote authenticated users to inject arbitrary web script or HTML via thezurmo · zurmo crm · CWE-79 | Düşük3,5 | — | %1,1 | 2 Tem 2015 |
- CVE-2019-1447224İzleyin
Zurmo 3.2.7-2 has XSS via the app/index.php/zurmo/default PATH_INFO.
OrtaCVSS 6,1İstismar yokEPSS %1zurmo · zurmo1 Ağu 2019
- CVE-2018-1665424İzleyin
Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1.
OrtaCVSS 6,1İstismar yokEPSS %1zurmo · zurmo crm7 Eyl 2018
- CVE-2017-718821İzleyin
Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl param
OrtaCVSS 5,4Kavram kanıtıEPSS %1zurmo · zurmo crm14 Nis 2017
- CVE-2017-1800421İzleyin
Zurmo 3.2.3 allows XSS via the latitude or longitude parameter to maps/default/mapAndPoint.
OrtaCVSS 5,4İstismar yokEPSS %1zurmo · zurmo crm31 Ara 2017
- CVE-2018-1959619İzleyin
Zurmo 3.2.4 allows HTML Injection via an admin's use of HTML in the report section, a related issue to CVE-2018-19506.
OrtaCVSS 4,8İstismar yokEPSS %1zurmo · zurmo19 Ara 2018
- CVE-2018-1950619İzleyin
Zurmo 3.2.4 has XSS via an admin's use of the name parameter in the reports section, aka the app/index.php/reports/default/details?id=1 URI.
OrtaCVSS 4,8İstismar yokEPSS %1zurmo · zurmo19 Ara 2018
- CVE-2017-1656919İzleyin
An Open URL Redirect issue exists in Zurmo 3.2.1.57987acc3018 via an http: URL in the redirectUrl parameter to app/index.php/meetings/defaul
OrtaCVSS 4,8İstismar yokEPSS %0zurmo · zurmo crm6 Kas 2017
- CVE-2017-1503919İzleyin
Cross-site scripting (XSS) exists in Zurmo 3.2.1.57987acc3018 via a data: URL in the redirectUrl parameter to app/index.php/meetings/default
OrtaCVSS 4,8İstismar yokEPSS %0zurmo · zurmo crm6 Kas 2017
- CVE-2015-536514İzleyin
Cross-site scripting (XSS) vulnerability in Zurmo CRM 3.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the
DüşükCVSS 3,5İstismar yokEPSS %1zurmo · zurmo crm2 Tem 2015