Vtiger CRM是美国Vtiger公司的一套基于SugarCRM开发的客户关系管理系统(CRM)。该管理系统提供管理、收集、分析客户信息等功能。 Vtiger CRM v7.2.0 存在信息泄露漏洞,该漏洞允许攻击者通过使用库和布局目录显示隐藏文件、列出目录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Vtiger CRM v7.2.0 contains a directory traversal vulnerability caused by improper access controls in /libraries and /layout directories, letting attackers display hidden files and list directories, exploit requires no authentication. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-19363.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-28483 | 7.1 HIGH | HTTP Response Splitting |
| CVE-2021-23326 | 6.3 MEDIUM | Command Injection |
| CVE-2020-28452 | 6.3 MEDIUM | Cross-site Request Forgery (CSRF) |
| CVE-2020-13134 | Tufin Securechange 跨站脚本漏洞 | |
| CVE-2020-35217 | Eclipse Vertx-web 跨站请求伪造漏洞 | |
| CVE-2021-3110 | Prestashop SQL注入漏洞 | |
| CVE-2021-3137 | XWiki 跨站脚本漏洞 | |
| CVE-2020-27851 | Rocketgenius Gravity Forms 跨站脚本漏洞 | |
| CVE-2020-27852 | Rocketgenius Gravity Forms 跨站脚本漏洞 | |
| CVE-2020-27850 | Rocketgenius Gravity Forms 跨站脚本漏洞 | |
| CVE-2020-13133 | Tufin Securechange 跨站脚本漏洞 | |
| CVE-2020-25684 | Dnsmasq 安全漏洞 | |
| CVE-2020-25385 | Nagios Log Server 跨站脚本漏洞 | |
| CVE-2020-19364 | OpenEMR 代码问题漏洞 | |
| CVE-2020-19362 | Vtiger CRM 跨站脚本漏洞 | |
| CVE-2020-19361 | MedinTux 跨站脚本漏洞 | |
| CVE-2020-19360 | FHEM 信息泄露漏洞 | |
| CVE-2020-25685 | dnsmasq 加密问题漏洞 | |
| CVE-2020-14360 | X.Org Server 缓冲区错误漏洞 | |
| CVE-2020-35239 | CakePHP 跨站请求伪造漏洞 |
Showing top 20 of 34 CVEs. View all on vendor page → →
No comments yet