dimo-crm CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

dimo-crm vulnerability overview

Aggregates CVE and security vulnerability intelligence across all dimo-crm-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk path handling and related problems; some flaws may lead to vendor impact file overwrite, affecting vendor surface production workloads and vendor surface software deployment scenarios.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2019-14768 An Arbitrary File Upload issue in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to deploy a new WebApp WAR file to the Tomcat server via Path Traversal, allowing remote code execution with SYSTEM privileges. [email protected] 8.8 2.61% 2020-01-21 2024-11-21
CVE-2019-14767 In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an unauthenticated user to download arbitrary files from the server. [email protected] 7.5 1.54% 2020-01-21 2024-11-21
CVE-2019-14766 Path Traversal in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to browse the server filesystem. [email protected] 6.5 0.53% 2020-01-21 2024-11-21
CVE-2019-14765 Incorrect Access Control in AfficheExplorateurParam() in DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to use administrative controllers. [email protected] 8.8 0.60% 2020-01-21 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence