Filtered by vendor Salesagility
Subscriptions
Total
83 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2018-20816 | 1 Salesagility | 1 Suitecrm | 2024-08-05 | N/A |
An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a phished URL, with script executed. | ||||
CVE-2018-15606 | 1 Salesagility | 1 Suitecrm | 2024-08-05 | N/A |
An XSS issue was discovered in SalesAgility SuiteCRM 7.x before 7.8.21 and 7.10.x before 7.10.8, related to phishing an error message. | ||||
CVE-2019-18784 | 1 Salesagility | 1 Suitecrm | 2024-08-05 | 9.8 Critical |
SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection. | ||||
CVE-2019-18782 | 1 Salesagility | 1 Suitecrm | 2024-08-05 | 5.3 Medium |
SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism. | ||||
CVE-2019-16922 | 1 Salesagility | 1 Suitecrm | 2024-08-05 | 5.3 Medium |
SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allows unintended public exposure of files. | ||||
CVE-2019-14752 | 1 Salesagility | 1 Suitecrm | 2024-08-05 | 6.1 Medium |
SuiteCRM 7.10.x and 7.11.x before 7.10.20 and 7.11.8 has XSS. | ||||
CVE-2019-14454 | 1 Salesagility | 1 Suitecrm | 2024-08-05 | 9.8 Critical |
SuiteCRM 7.11.x and 7.10.x before 7.11.8 and 7.10.20 is vulnerable to vertical privilege escalation. | ||||
CVE-2019-13335 | 1 Salesagility | 1 Suitecrm | 2024-08-04 | 9.8 Critical |
SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF. | ||||
CVE-2019-12598 | 1 Salesagility | 1 Suitecrm | 2024-08-04 | N/A |
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3). | ||||
CVE-2019-12600 | 1 Salesagility | 1 Suitecrm | 2024-08-04 | N/A |
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3). | ||||
CVE-2019-12601 | 1 Salesagility | 1 Suitecrm | 2024-08-04 | N/A |
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 3 of 3). | ||||
CVE-2019-12599 | 1 Salesagility | 1 Suitecrm | 2024-08-04 | N/A |
SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection. | ||||
CVE-2019-6506 | 1 Salesagility | 1 Suitecrm | 2024-08-04 | N/A |
SuiteCRM before 7.8.28, 7.9.x and 7.10.x before 7.10.15, and 7.11.x before 7.11.3 allows SQL Injection. | ||||
CVE-2020-28328 | 1 Salesagility | 1 Suitecrm | 2024-08-04 | 8.8 High |
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root. | ||||
CVE-2020-15301 | 1 Salesagility | 1 Suitecrm | 2024-08-04 | 7.8 High |
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation. | ||||
CVE-2020-15300 | 1 Salesagility | 1 Suitecrm | 2024-08-04 | 6.1 Medium |
SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document. | ||||
CVE-2020-14208 | 1 Salesagility | 1 Suitecrm | 2024-08-04 | 5.4 Medium |
SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML. | ||||
CVE-2020-8785 | 1 Salesagility | 1 Suitecrm | 2024-08-04 | 9.8 Critical |
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4). | ||||
CVE-2020-8786 | 1 Salesagility | 1 Suitecrm | 2024-08-04 | 9.8 Critical |
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4). | ||||
CVE-2020-8804 | 1 Salesagility | 1 Suitecrm | 2024-08-04 | 6.5 Medium |
SuiteCRM through 7.11.10 allows SQL Injection via the SOAP API, the EmailUIAjax interface, or the MailMerge module. |