YetiForceCrm是波兰YetiForce公司的一个开源的 Crm 系统。 YetiForceCrm 存在跨站脚本漏洞,该漏洞源于管理员在使用数据库信息功能时,会通过两种情况意外调用并执行恶意代码:(1)具有数据库访问权限的内部攻击者(本地)可以通过在数据库中创建表将恶意内容插入到字段中;(2)系统管理员恶意导入未知来源的数据库。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| yetiforcecompany | yetiforcecompany/yetiforcecrm | unspecified ~ 6.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet