YetiForceCompany/YetiForceCRM

YetiForceCompany/YetiForceCRM

Releases36
Frequency3 months 17 hours
Last Release
Stars1.79K
We've moved! For more information, visit https://github.com/YetiForceCompany/YetiForce

CVE History

CVEPublishedCVSS v3CVSS v2
6.5 MEDIUM

Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component.

5.4 MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

5.4 MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

5.4 MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

5.4 MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

5.4 MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.3.

5.4 MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

5.4 MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

5.4 MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

4.8 MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

6.1 MEDIUM4.3 MEDIUM

Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover.

8 HIGH6 MEDIUM

Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.

6.1 MEDIUM4.3 MEDIUM

yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

4.3 MEDIUM4 MEDIUM

yetiforcecrm is vulnerable to Business Logic Errors

5.4 MEDIUM3.5 LOW

yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

4.3 MEDIUM4 MEDIUM

yetiforcecrm is vulnerable to Business Logic Errors

6.1 MEDIUM4.3 MEDIUM

yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

4.3 MEDIUM4.3 MEDIUM

yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)