Loading HuntDB...

Vulnerabilities

CVE-2022-3002

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

Published Oct 06, 2022

CVE-2022-3005

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

Published Sep 20, 2022

CVE-2022-3004

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

Published Sep 20, 2022

CVE-2022-3000

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

Published Sep 20, 2022

CVE-2022-2924

HIGH

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.3.

Published Sep 20, 2022

CVE-2022-2829

HIGH

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

Published Aug 23, 2022

CVE-2022-2890

CRITICAL

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

Published Aug 22, 2022

CVE-2022-1340

HIGH

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

Published Aug 22, 2022

CVE-2022-2885

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

Published Aug 21, 2022

CVE-2022-1411

CRITICAL

Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover.

Published May 05, 2022

CVE-2022-0269

HIGH

Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.

Published Jan 24, 2022

CVE-2021-4121

MEDIUM

yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Published Dec 16, 2021

CVE-2021-4117

HIGH

yetiforcecrm is vulnerable to Business Logic Errors

Published Dec 15, 2021

CVE-2021-4116

MEDIUM

yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Published Dec 15, 2021

CVE-2021-4111

HIGH

yetiforcecrm is vulnerable to Business Logic Errors

Published Dec 15, 2021

CVE-2021-4107

MEDIUM

yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Published Dec 14, 2021

CVE-2021-4092

MEDIUM

yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)

Published Dec 11, 2021