Skip to main content

Vendor archive

xrms_crm_project CVEs

Beta · best-effort

2 CVEs tagged to vendor xrms_crm_project0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2014-5520

Published Oct 26, 2014

SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via the user_id parameter to plugins/webform/new-form.php, whic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-5521

Published Sep 2, 2014

plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in the username parameter.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1