Bottelet Daybyday Crm是Bottelet个人开发者的一个用于任务、时间、员工、休假管理的建站系统。 Daybyday CRM 中存在跨站脚本漏洞,该漏洞源于产品新任务的标题字段未对用户输入数据做有效验证。攻击者可通过诱导用户打开任务页面查看所有任务时触发该漏洞导致客户端代码执行。 以下产品及版本受到影响:Daybyday CRM 2.2.0 版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Bottelet | DaybydayCRM | 2.2.0 | - |
|
| Bottelet | flarepoint | 2.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-22111 | 8.8 HIGH | DayByDay CRM - Missing Authorization when Changing Password |
| CVE-2022-22110 | 7.5 HIGH | DayByDay CRM - Weak Password Requirements in Update User |
| CVE-2022-22107 | 4.3 MEDIUM | DayByDay CRM - Missing Authorization when Viewing Appointments |
| CVE-2022-22108 | 4.3 MEDIUM | DayByDay CRM - Missing Authorization when Viewing Absences |
No comments yet