Vulnerabilities > Dimo CRM
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-01-21 | CVE-2019-14768 | Path Traversal vulnerability in Dimo-Crm Yellowbox CRM An Arbitrary File Upload issue in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to deploy a new WebApp WAR file to the Tomcat server via Path Traversal, allowing remote code execution with SYSTEM privileges. | 8.8 |
2020-01-21 | CVE-2019-14767 | Path Traversal vulnerability in Dimo-Crm Yellowbox CRM In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an unauthenticated user to download arbitrary files from the server. | 7.5 |
2020-01-21 | CVE-2019-14766 | Path Traversal vulnerability in Dimo-Crm Yellowbox CRM Path Traversal in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to browse the server filesystem. | 6.5 |
2020-01-21 | CVE-2019-14765 | Unspecified vulnerability in Dimo-Crm Yellowbox CRM Incorrect Access Control in AfficheExplorateurParam() in DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to use administrative controllers. | 8.8 |