Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Xrms Crm Project Subscribe
Filtered by product Xrms Crm
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-5520 1 Xrms Crm Project 1 Xrms Crm 2014-10-30 7.5 HIGH N/A
SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via the user_id parameter to plugins/webform/new-form.php, which is not properly handled by plugins/useradmin/fingeruser.php.
CVE-2014-5521 1 Xrms Crm Project 1 Xrms Crm 2014-09-03 6.5 MEDIUM N/A
plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in the username parameter.