Yetiforce Yetiforce-Crm vulnerabilities
17 known vulnerabilities affecting yetiforce/yetiforce-crm.
Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM15
Vulnerabilities
Page 1 of 1
CVE-2023-49508MEDIUM≥ 0, < 6.5.02024-02-16
CVE-2023-49508 [MEDIUM] CWE-22 YetiForceCRM Directory Traversal vulnerability
YetiForceCRM Directory Traversal vulnerability
Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component.
ghsaosv
CVE-2022-3002MEDIUM≥ 0, ≤ 6.4.02022-10-06
CVE-2022-3002 [MEDIUM] CWE-79 YetiForce CRM vulnerable to stored Cross-site Scripting
YetiForce CRM vulnerable to stored Cross-site Scripting
YetiForce CRM version 6.4.0 and prior is vulnerable to stored cross-site scripting. A [patch](https://github.com/yetiforcecompany/yetiforcecrm/commit/54728becfdad9b6e686bbe336007cba2ce518248) is available on the `developer` branch.
ghsaosv
CVE-2022-2924MEDIUM≥ 0, ≤ 6.4.02022-09-21
CVE-2022-2924 [MEDIUM] CWE-79 YetiForce CRM vulnerable to stored Cross-site Scripting via WidgetsManagement module
YetiForce CRM vulnerable to stored Cross-site Scripting via WidgetsManagement module
YetiForce CRM versions 6.4.0 and prior are vulnerable to cross-site scripting via the `WidgetsManagement` module. A patch is available at commit b716ecea340783b842498425faa029800bd30420.
ghsaosv
CVE-2022-3004MEDIUM≥ 0, ≤ 6.4.02022-09-21
CVE-2022-3004 [MEDIUM] CWE-79 YetiForce CRM vulnerable to stored Cross-site Scripting via WorkFlow module
YetiForce CRM vulnerable to stored Cross-site Scripting via WorkFlow module
YetiForce CRM versions 6.4.0 and prior are vulnerable to cross-site scripting via the `WorkFlow` module. A patch is available at commit cd82ecce44d83f1f6c10c7766bf36f3026de024a.
ghsaosv
CVE-2022-3005MEDIUM≥ 0, ≤ 6.4.02022-09-21
CVE-2022-3005 [MEDIUM] CWE-79 YetiForce CRM vulnerable to stored Cross-site Scripting via SlaPolicy module
YetiForce CRM vulnerable to stored Cross-site Scripting via SlaPolicy module
YetiForce CRM versions 6.4.0 and prior are vulnerable to cross-site scripting via the `SlaPolicy` module. A patch is available at commit e55886781509fe39951fc7528347696474a17884.
ghsaosv
CVE-2022-3000MEDIUM≥ 0, ≤ 6.4.02022-09-21
CVE-2022-3000 [MEDIUM] CWE-79 YetiForce CRM vulnerable to stored Cross-site Scripting via LayoutEditor module
YetiForce CRM vulnerable to stored Cross-site Scripting via LayoutEditor module
YetiForce CRM versions 6.4.0 and prior are vulnerable to cross-site scripting via the `LayoutEditor` module. A patch is available at commit eebc12601495ada38495076bec12841b2477516b.
ghsaosv
CVE-2022-1340MEDIUM≥ 0, < 6.4.02022-08-23
CVE-2022-1340 [MEDIUM] CWE-79 Cross site scripting in yetiforce/yetiforce-crm
Cross site scripting in yetiforce/yetiforce-crm
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
ghsaosv
CVE-2022-2890MEDIUM≥ 0, < 6.4.02022-08-23
CVE-2022-2890 [MEDIUM] CWE-79 Cross site scripting in yetiforce/yetiforce-crm
Cross site scripting in yetiforce/yetiforce-crm
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
ghsaosv
CVE-2022-2885MEDIUM≥ 0, < 6.4.02022-08-22
CVE-2022-2885 [MEDIUM] CWE-79 Cross site scripting in yetiforce/yetiforce-crm
Cross site scripting in yetiforce/yetiforce-crm
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
ghsaosv
CVE-2022-1411MEDIUM≥ 0, < 6.4.02022-05-06
CVE-2022-1411 [MEDIUM] CWE-434 Unrestricted Upload of File with Dangerous Type in yetiforce-crm
Unrestricted Upload of File with Dangerous Type in yetiforce-crm
Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover.
ghsaosv
CVE-2022-0269HIGH≥ 0, ≤ 6.3.02022-01-27
CVE-2022-0269 [HIGH] CWE-352 Cross-Site Request Forgery in yetiforce
Cross-Site Request Forgery in yetiforce
Versions of yetiforce 6.3.0 and prior are subject to privilege escalation via a cross site request forgery bug. This allows an attacker to create a new admin account even with SameSite: Strict enabled. This vulnerability can be exploited by any user on the system including guest users.
ghsaosv
CVE-2021-4121MEDIUM≥ 0, ≤ 6.3.02021-12-17
CVE-2021-4121 [MEDIUM] CWE-79 yetiforcecrm is vulnerable to Cross-site Scripting
yetiforcecrm is vulnerable to Cross-site Scripting
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
ghsaosv
CVE-2021-4111HIGH≥ 0, ≤ 6.3.02021-12-16
CVE-2021-4111 [HIGH] CWE-20 YetiForceCRM is vulnerable to Business Logic Errors because product amount can be a negative number
YetiForceCRM is vulnerable to Business Logic Errors because product amount can be a negative number
YetiForceCRM is vulnerable to Business Logic Errors because product amount can be a negative number.
ghsaosv
CVE-2021-4107MEDIUM≥ 0, ≤ 6.3.02021-12-16
CVE-2021-4107 [MEDIUM] CWE-79 yetiforcecrm is vulnerable to Cross-site Scripting
yetiforcecrm is vulnerable to Cross-site Scripting
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
ghsaosv
CVE-2021-4117MEDIUM≥ 0, ≤ 6.3.02021-12-16
CVE-2021-4117 [MEDIUM] CWE-20 YetiForceCRM is vulnerable to Business Logic Errors in the weight of a product
YetiForceCRM is vulnerable to Business Logic Errors in the weight of a product
YetiForceCRM is vulnerable to Business Logic Errors in the Weight of a Product since that value can be a negative number.
ghsaosv
CVE-2021-4092MEDIUM≥ 0, < 6.3.02021-12-16
CVE-2021-4092 [MEDIUM] CWE-352 yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)
yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)
yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF).
ghsaosv
CVE-2021-4116MEDIUM≥ 0, ≤ 6.3.02021-12-16
CVE-2021-4116 [MEDIUM] CWE-79 yetiforcecrm is vulnerable to Cross-site Scripting
yetiforcecrm is vulnerable to Cross-site Scripting
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
ghsaosv