Vulnerabilities > Vtenext > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-09-14 | CVE-2020-10229 | Cross-Site Request Forgery (CSRF) vulnerability in Vtenext 19 A CSRF issue in vtecrm vtenext 19 CE allows attackers to carry out unwanted actions on an administrator's behalf, such as uploading files, adding users, and deleting accounts. | 8.8 |
2020-09-14 | CVE-2020-10228 | Unrestricted Upload of File with Dangerous Type vulnerability in Vtenext 19 A file upload vulnerability in vtecrm vtenext 19 CE allows authenticated users to upload files with a .pht extension, resulting in remote code execution. | 8.8 |