Vulnerabilities (CVE)

Filtered by vendor Vtiger Subscribe
Filtered by product Vtiger Crm
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-19362 1 Vtiger 1 Vtiger Crm 2021-01-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page.
CVE-2020-19363 1 Vtiger 1 Vtiger Crm 2021-01-22 4.3 MEDIUM 6.5 MEDIUM
Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.
CVE-2018-8047 1 Vtiger 1 Vtiger Crm 2019-06-07 4.3 MEDIUM 6.1 MEDIUM
vtiger CRM 7.0.1 is affected by one reflected Cross-Site Scripting (XSS) vulnerability affecting version 7.0.1 and probably prior versions. This vulnerability could allow remote unauthenticated attackers to inject arbitrary web script or HTML via index.php?module=Contacts&view=List (app parameter).