YetiForceCrm是波兰YetiForce公司的一个开源的 Crm 系统。 YetiForceCrm 6.4.0之前的版本存在跨站脚本漏洞,该漏洞源于其在Settings中的SlaPolicy模块上,“Text”类型的recordModel->name参数未经验证且在SlaPolicy/EditViewBlocks.tpl上直接使用但并未编码或验证。它允许攻击者注入任意 Javascript 代码来执行存储的 XSS 攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| yetiforcecompany | yetiforcecompany/yetiforcecrm | unspecified ~ 6.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-2924 | Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm | |
| CVE-2022-3000 | Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm | |
| CVE-2022-3004 | Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm |
No comments yet