Yetiforce Yetiforce-Crm vulnerabilities

17 known vulnerabilities affecting yetiforce/yetiforce-crm.

Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM15

Vulnerabilities

Page 1 of 1
CVE-2023-49508MEDIUM≥ 0, < 6.5.02024-02-16
CVE-2023-49508 [MEDIUM] CWE-22 YetiForceCRM Directory Traversal vulnerability YetiForceCRM Directory Traversal vulnerability Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component.
ghsaosv
CVE-2022-3002MEDIUM≥ 0, ≤ 6.4.02022-10-06
CVE-2022-3002 [MEDIUM] CWE-79 YetiForce CRM vulnerable to stored Cross-site Scripting YetiForce CRM vulnerable to stored Cross-site Scripting YetiForce CRM version 6.4.0 and prior is vulnerable to stored cross-site scripting. A [patch](https://github.com/yetiforcecompany/yetiforcecrm/commit/54728becfdad9b6e686bbe336007cba2ce518248) is available on the `developer` branch.
ghsaosv
CVE-2022-2924MEDIUM≥ 0, ≤ 6.4.02022-09-21
CVE-2022-2924 [MEDIUM] CWE-79 YetiForce CRM vulnerable to stored Cross-site Scripting via WidgetsManagement module YetiForce CRM vulnerable to stored Cross-site Scripting via WidgetsManagement module YetiForce CRM versions 6.4.0 and prior are vulnerable to cross-site scripting via the `WidgetsManagement` module. A patch is available at commit b716ecea340783b842498425faa029800bd30420.
ghsaosv
CVE-2022-3004MEDIUM≥ 0, ≤ 6.4.02022-09-21
CVE-2022-3004 [MEDIUM] CWE-79 YetiForce CRM vulnerable to stored Cross-site Scripting via WorkFlow module YetiForce CRM vulnerable to stored Cross-site Scripting via WorkFlow module YetiForce CRM versions 6.4.0 and prior are vulnerable to cross-site scripting via the `WorkFlow` module. A patch is available at commit cd82ecce44d83f1f6c10c7766bf36f3026de024a.
ghsaosv
CVE-2022-3005MEDIUM≥ 0, ≤ 6.4.02022-09-21
CVE-2022-3005 [MEDIUM] CWE-79 YetiForce CRM vulnerable to stored Cross-site Scripting via SlaPolicy module YetiForce CRM vulnerable to stored Cross-site Scripting via SlaPolicy module YetiForce CRM versions 6.4.0 and prior are vulnerable to cross-site scripting via the `SlaPolicy` module. A patch is available at commit e55886781509fe39951fc7528347696474a17884.
ghsaosv
CVE-2022-3000MEDIUM≥ 0, ≤ 6.4.02022-09-21
CVE-2022-3000 [MEDIUM] CWE-79 YetiForce CRM vulnerable to stored Cross-site Scripting via LayoutEditor module YetiForce CRM vulnerable to stored Cross-site Scripting via LayoutEditor module YetiForce CRM versions 6.4.0 and prior are vulnerable to cross-site scripting via the `LayoutEditor` module. A patch is available at commit eebc12601495ada38495076bec12841b2477516b.
ghsaosv
CVE-2022-1340MEDIUM≥ 0, < 6.4.02022-08-23
CVE-2022-1340 [MEDIUM] CWE-79 Cross site scripting in yetiforce/yetiforce-crm Cross site scripting in yetiforce/yetiforce-crm Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
ghsaosv
CVE-2022-2890MEDIUM≥ 0, < 6.4.02022-08-23
CVE-2022-2890 [MEDIUM] CWE-79 Cross site scripting in yetiforce/yetiforce-crm Cross site scripting in yetiforce/yetiforce-crm Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
ghsaosv
CVE-2022-2885MEDIUM≥ 0, < 6.4.02022-08-22
CVE-2022-2885 [MEDIUM] CWE-79 Cross site scripting in yetiforce/yetiforce-crm Cross site scripting in yetiforce/yetiforce-crm Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
ghsaosv
CVE-2022-1411MEDIUM≥ 0, < 6.4.02022-05-06
CVE-2022-1411 [MEDIUM] CWE-434 Unrestricted Upload of File with Dangerous Type in yetiforce-crm Unrestricted Upload of File with Dangerous Type in yetiforce-crm Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover.
ghsaosv
CVE-2022-0269HIGH≥ 0, ≤ 6.3.02022-01-27
CVE-2022-0269 [HIGH] CWE-352 Cross-Site Request Forgery in yetiforce Cross-Site Request Forgery in yetiforce Versions of yetiforce 6.3.0 and prior are subject to privilege escalation via a cross site request forgery bug. This allows an attacker to create a new admin account even with SameSite: Strict enabled. This vulnerability can be exploited by any user on the system including guest users.
ghsaosv
CVE-2021-4121MEDIUM≥ 0, ≤ 6.3.02021-12-17
CVE-2021-4121 [MEDIUM] CWE-79 yetiforcecrm is vulnerable to Cross-site Scripting yetiforcecrm is vulnerable to Cross-site Scripting yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
ghsaosv
CVE-2021-4111HIGH≥ 0, ≤ 6.3.02021-12-16
CVE-2021-4111 [HIGH] CWE-20 YetiForceCRM is vulnerable to Business Logic Errors because product amount can be a negative number YetiForceCRM is vulnerable to Business Logic Errors because product amount can be a negative number YetiForceCRM is vulnerable to Business Logic Errors because product amount can be a negative number.
ghsaosv
CVE-2021-4107MEDIUM≥ 0, ≤ 6.3.02021-12-16
CVE-2021-4107 [MEDIUM] CWE-79 yetiforcecrm is vulnerable to Cross-site Scripting yetiforcecrm is vulnerable to Cross-site Scripting yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
ghsaosv
CVE-2021-4117MEDIUM≥ 0, ≤ 6.3.02021-12-16
CVE-2021-4117 [MEDIUM] CWE-20 YetiForceCRM is vulnerable to Business Logic Errors in the weight of a product YetiForceCRM is vulnerable to Business Logic Errors in the weight of a product YetiForceCRM is vulnerable to Business Logic Errors in the Weight of a Product since that value can be a negative number.
ghsaosv
CVE-2021-4092MEDIUM≥ 0, < 6.3.02021-12-16
CVE-2021-4092 [MEDIUM] CWE-352 yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF) yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF) yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF).
ghsaosv
CVE-2021-4116MEDIUM≥ 0, ≤ 6.3.02021-12-16
CVE-2021-4116 [MEDIUM] CWE-79 yetiforcecrm is vulnerable to Cross-site Scripting yetiforcecrm is vulnerable to Cross-site Scripting yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
ghsaosv