Vulnerabilities > 07Fly > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-01-16 CVE-2024-57160 Cross-Site Request Forgery (CSRF) vulnerability in 07Fly Customer Relationship Management 1.3.9
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html.
network
low complexity
07fly CWE-352
4.3
2025-01-16 CVE-2024-57161 Cross-Site Request Forgery (CSRF) vulnerability in 07Fly Customer Relationship Management 1.3.9
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html
network
low complexity
07fly CWE-352
4.3
2023-06-02 CVE-2023-3058 Cross-site Scripting vulnerability in 07Fly Customer Relationship Management 1.2.0
A vulnerability was found in 07FLY CRM up to 1.2.0.
network
low complexity
07fly CWE-79
5.4