Bottelet Daybyday Crm是Bottelet个人开发者的一个用于任务、时间、员工、休假管理的建站系统。 DayByDay CRM 中存在授权问题漏洞,该漏洞源于产品允许启动更新用户权限的用户修改任意用户的密码。以下产品及版本受到影响:DayByDay CRM 2.2.0 版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Bottelet | DaybydayCRM | 2.2.0 | - |
|
| Bottelet | flarepoint | 2.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-22110 | 7.5 HIGH | DayByDay CRM - Weak Password Requirements in Update User |
| CVE-2022-22109 | 5.4 MEDIUM | DayByDay CRM - Stored Cross-Site Scripting (XSS) in Task Title |
| CVE-2022-22107 | 4.3 MEDIUM | DayByDay CRM - Missing Authorization when Viewing Appointments |
| CVE-2022-22108 | 4.3 MEDIUM | DayByDay CRM - Missing Authorization when Viewing Absences |
No comments yet