Yetiforcecompany Yetiforcecrm vulnerabilities
17 known vulnerabilities affecting yetiforcecompany/yetiforcecompany_yetiforcecrm.
Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM16
Vulnerabilities
Page 1 of 1
CVE-2022-3002MEDIUMCVSS 5.4≥ unspecified, < 6.4.02022-10-06
CVE-2022-3002 [MEDIUM] CWE-79 CVE-2022-3002: Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
cvelistv5nvd
CVE-2022-3005MEDIUMCVSS 5.4≥ unspecified, < 6.4.02022-09-20
CVE-2022-3005 [MEDIUM] CWE-79 CVE-2022-3005: Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
cvelistv5nvd
CVE-2022-3000MEDIUMCVSS 5.4≥ unspecified, < 6.4.02022-09-20
CVE-2022-3000 [MEDIUM] CWE-79 CVE-2022-3000: Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
cvelistv5nvd
CVE-2022-2924MEDIUMCVSS 5.4≥ unspecified, < 6.32022-09-20
CVE-2022-2924 [MEDIUM] CWE-79 CVE-2022-2924: Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.3.
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.3.
cvelistv5nvd
CVE-2022-3004MEDIUMCVSS 5.4≥ unspecified, < 6.4.02022-09-20
CVE-2022-3004 [MEDIUM] CWE-79 CVE-2022-3004: Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
cvelistv5nvd
CVE-2022-2829MEDIUMCVSS 5.4≥ unspecified, < 6.4.02022-08-23
CVE-2022-2829 [MEDIUM] CWE-79 CVE-2022-2829: Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
cvelistv5nvd
CVE-2022-1340MEDIUMCVSS 5.4≥ unspecified, < 6.4.02022-08-22
CVE-2022-1340 [MEDIUM] CWE-79 CVE-2022-1340: Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
cvelistv5nvd
CVE-2022-2890MEDIUMCVSS 5.4≥ unspecified, < 6.4.02022-08-22
CVE-2022-2890 [MEDIUM] CWE-79 CVE-2022-2890: Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
cvelistv5nvd
CVE-2022-2885MEDIUMCVSS 4.8≥ unspecified, < 6.4.02022-08-21
CVE-2022-2885 [MEDIUM] CWE-79 CVE-2022-2885: Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
cvelistv5nvd
CVE-2022-1411MEDIUMCVSS 6.1≥ unspecified, < 6.4.02022-05-05
CVE-2022-1411 [MEDIUM] CWE-434 CVE-2022-1411: Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker
Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover.
cvelistv5nvd
CVE-2022-0269HIGHCVSS 8.0≥ unspecified, < 6.3.02022-01-24
CVE-2022-0269 [HIGH] CWE-352 CVE-2022-0269: Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.
Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.
cvelistv5nvd
CVE-2021-4121MEDIUMCVSS 6.1≥ unspecified, < 6.4.02021-12-16
CVE-2021-4121 [MEDIUM] CWE-79 CVE-2021-4121: yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-si
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
cvelistv5nvd
CVE-2021-4117MEDIUMCVSS 4.3≥ unspecified, < 6.4.02021-12-15
CVE-2021-4117 [MEDIUM] CWE-840 CVE-2021-4117: yetiforcecrm is vulnerable to Business Logic Errors
yetiforcecrm is vulnerable to Business Logic Errors
cvelistv5nvd
CVE-2021-4111MEDIUMCVSS 4.3≥ unspecified, < 6.4.02021-12-15
CVE-2021-4111 [MEDIUM] CWE-840 CVE-2021-4111: yetiforcecrm is vulnerable to Business Logic Errors
yetiforcecrm is vulnerable to Business Logic Errors
cvelistv5nvd
CVE-2021-4116MEDIUMCVSS 5.4≥ unspecified, < 6.4.02021-12-15
CVE-2021-4116 [MEDIUM] CWE-79 CVE-2021-4116: yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-si
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
cvelistv5nvd
CVE-2021-4107MEDIUMCVSS 6.1≥ unspecified, < 6.4.02021-12-14
CVE-2021-4107 [MEDIUM] CWE-79 CVE-2021-4107: yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-si
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
cvelistv5nvd
CVE-2021-4092MEDIUMCVSS 4.3≥ unspecified, < 6.3.02021-12-11
CVE-2021-4092 [MEDIUM] CWE-352 CVE-2021-4092: yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)
yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)
cvelistv5nvd