Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vtiger vtiger crm 5.2.1 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2013-3213
Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 up to and including 5.4.0 allow remote malicious users to execute arbitrary SQL commands via the (1) picklist_name parameter in the get_picklists method to soap/customerportal.php, (2) where parameter in the get_tickets_l...
Vtiger Vtiger Crm 5.0.3
Vtiger Vtiger Crm 5.0.1
Vtiger Vtiger Crm 5.3.0
Vtiger Vtiger Crm 5.1.0
Vtiger Vtiger Crm 5.2.0
Vtiger Vtiger Crm 5.0.4
Vtiger Vtiger Crm 5.4.0
Vtiger Vtiger Crm 5.0.0
Vtiger Vtiger Crm 5.0.2
Vtiger Vtiger Crm 5.2.1
1 EDB exploit
NA
CVE-2011-4680
Multiple cross-site scripting (XSS) vulnerabilities in the customer portal in vtiger CRM prior to 5.2.0 allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Vtiger Vtiger Crm 3
Vtiger Vtiger Crm 5.0.3
Vtiger Vtiger Crm 4.2
Vtiger Vtiger Crm 2.0.1
Vtiger Vtiger Crm 2.0
Vtiger Vtiger Crm 5.0.4
Vtiger Vtiger Crm 2.1
Vtiger Vtiger Crm 5.1.0
Vtiger Vtiger Crm 4
Vtiger Vtiger Crm 4.0
Vtiger Vtiger Crm 3.0
Vtiger Vtiger Crm
Vtiger Vtiger Crm 5.0.0
Vtiger Vtiger Crm 5.0.2
Vtiger Vtiger Crm 3.2
Vtiger Vtiger Crm 1.0
Vtiger Vtiger Crm 4.2.4
Vtiger Vtiger Crm 5.2.1
Vtiger Vtiger Crm 4.0.1
NA
CVE-2013-5091
SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated users to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php. NOTE: this issue might be a duplicate of CVE-2011-4559.
Vtiger Vtiger Crm 5.0.3
Vtiger Vtiger Crm 5.3.0
Vtiger Vtiger Crm 4.2
Vtiger Vtiger Crm 5.1.0
Vtiger Vtiger Crm 5.2.0
Vtiger Vtiger Crm 2.0.1
Vtiger Vtiger Crm 2.0
Vtiger Vtiger Crm 5.0.4
Vtiger Vtiger Crm 2.1
Vtiger Vtiger Crm 4
Vtiger Vtiger Crm 4.0
Vtiger Vtiger Crm 3.0
Vtiger Vtiger Crm 5.0.0
Vtiger Vtiger Crm 5.0.2
Vtiger Vtiger Crm 3.2
Vtiger Vtiger Crm
Vtiger Vtiger Crm 1.0
Vtiger Vtiger Crm 4.2.4
Vtiger Vtiger Crm 5.2.1
Vtiger Vtiger Crm 4.0.1
1 EDB exploit
NA
CVE-2014-2268
views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote malicious users to re-install the application via a request that sets the X-Requested-With HTTP header, as demonstrated by executing arbitrary PHP co...
Vtiger Vtiger Crm 5.0.3
Vtiger Vtiger Crm 5.0.1
Vtiger Vtiger Crm 5.3.0
Vtiger Vtiger Crm 5.1.0
Vtiger Vtiger Crm 5.2.0
Vtiger Vtiger Crm 2.0.1
Vtiger Vtiger Crm 2.0
Vtiger Vtiger Crm 4.2
Vtiger Vtiger Crm 5.0.4
Vtiger Vtiger Crm 6.0.0
Vtiger Vtiger Crm 5.4.0
Vtiger Vtiger Crm 2.1
Vtiger Vtiger Crm 4
Vtiger Vtiger Crm 4.0
Vtiger Vtiger Crm 3.0
Vtiger Vtiger Crm 5.0.0
Vtiger Vtiger Crm 5.0.2
Vtiger Vtiger Crm 3.2
Vtiger Vtiger Crm 1.0
Vtiger Vtiger Crm 4.2.4
Vtiger Vtiger Crm 5.2.1
Vtiger Vtiger Crm 4.0.1
1 EDB exploit
NA
CVE-2011-4559
SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and previous versions allows remote malicious users to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php.
Vtiger Vtiger Crm 5.0.3
Vtiger Vtiger Crm
Vtiger Vtiger Crm 5.1.0
Vtiger Vtiger Crm 5.2.0
Vtiger Vtiger Crm 2.0.1
Vtiger Vtiger Crm 2.0
Vtiger Vtiger Crm 4.2
Vtiger Vtiger Crm 5.0.4
Vtiger Vtiger Crm 2.1
Vtiger Vtiger Crm 4.0
Vtiger Vtiger Crm 3.0
Vtiger Vtiger Crm 5.0.2
Vtiger Vtiger Crm 3.2
Vtiger Vtiger Crm 1.0
Vtiger Vtiger Crm 4.2.4
Vtiger Vtiger Crm 4.0.1
1 EDB exploit
NA
CVE-2010-3910
Multiple directory traversal vulnerabilities in the return_application_language function in include/utils/utils.php in vtiger CRM prior to 5.2.1 allow remote malicious users to include and execute arbitrary local files via a .. (dot dot) in (1) the lang_crm parameter to phprint.p...
Vtiger Vtiger Crm 3
Vtiger Vtiger Crm 5.0.3
Vtiger Vtiger Crm
Vtiger Vtiger Crm 5.1.0
Vtiger Vtiger Crm 2.0.1
Vtiger Vtiger Crm 2.0
Vtiger Vtiger Crm 4.2
Vtiger Vtiger Crm 5.0.4
Vtiger Vtiger Crm 2.1
Vtiger Vtiger Crm 4
Vtiger Vtiger Crm 4.0
Vtiger Vtiger Crm 3.0
Vtiger Vtiger Crm 5.0.0
Vtiger Vtiger Crm 5.0.2
Vtiger Vtiger Crm 3.2
Vtiger Vtiger Crm 1.0
Vtiger Vtiger Crm 4.2.4
Vtiger Vtiger Crm 4.0.1
NA
CVE-2010-3909
Incomplete blacklist vulnerability in config.template.php in vtiger CRM prior to 5.2.1 allows remote authenticated users to execute arbitrary code by using the draft save feature in the Compose Mail component to upload a file with a .phtml extension, and then accessing this file ...
Vtiger Vtiger Crm 3
Vtiger Vtiger Crm 5.0.3
Vtiger Vtiger Crm
Vtiger Vtiger Crm 5.1.0
Vtiger Vtiger Crm 2.0.1
Vtiger Vtiger Crm 2.0
Vtiger Vtiger Crm 4.2
Vtiger Vtiger Crm 5.0.4
Vtiger Vtiger Crm 2.1
Vtiger Vtiger Crm 4
Vtiger Vtiger Crm 4.0
Vtiger Vtiger Crm 3.0
Vtiger Vtiger Crm 5.0.0
Vtiger Vtiger Crm 5.0.2
Vtiger Vtiger Crm 3.2
Vtiger Vtiger Crm 1.0
Vtiger Vtiger Crm 4.2.4
Vtiger Vtiger Crm 4.0.1
NA
CVE-2010-3911
Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM prior to 5.2.1 allow remote malicious users to inject arbitrary web script or HTML via (1) the username (aka default_user_name) field or (2) the password field in a Users Login action to index.php, or (3) the label...
Vtiger Vtiger Crm 3
Vtiger Vtiger Crm 5.0.3
Vtiger Vtiger Crm
Vtiger Vtiger Crm 5.1.0
Vtiger Vtiger Crm 2.0.1
Vtiger Vtiger Crm 2.0
Vtiger Vtiger Crm 4.2
Vtiger Vtiger Crm 5.0.4
Vtiger Vtiger Crm 2.1
Vtiger Vtiger Crm 4
Vtiger Vtiger Crm 4.0
Vtiger Vtiger Crm 3.0
Vtiger Vtiger Crm 5.0.0
Vtiger Vtiger Crm 5.0.2
Vtiger Vtiger Crm 3.2
Vtiger Vtiger Crm 1.0
Vtiger Vtiger Crm 4.2.4
Vtiger Vtiger Crm 4.0.1
NA
CVE-2011-4670
Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 5.2.1 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) viewname parameter in a CalendarAjax action, (2) activity_mode parameter in a DetailView action, (3) conta...
Vtiger Vtiger Crm
2 EDB exploits
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started