Vulnerabilities > Webkul > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-10-07 | CVE-2024-45932 | Cross-site Scripting vulnerability in Webkul Krayin CRM 1.3.0 Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2. | 4.8 |
2024-01-17 | CVE-2023-36235 | Authorization Bypass Through User-Controlled Key vulnerability in Webkul Qloapps An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter. | 6.5 |
2024-01-16 | CVE-2023-36236 | Cross-site Scripting vulnerability in Webkul Bagisto Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad. | 4.8 |
2023-10-23 | CVE-2023-37636 | Cross-site Scripting vulnerability in Webkul Uvdesk 1.1.1 A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket. | 5.4 |
2023-06-23 | CVE-2023-36287 | Cross-site Scripting vulnerability in Webkul Qloapps 1.6.0 An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST controller parameter. | 6.1 |
2023-06-23 | CVE-2023-36288 | Cross-site Scripting vulnerability in Webkul Qloapps 1.6.0 An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via GET configure parameter. | 5.4 |
2023-06-23 | CVE-2023-36289 | Cross-site Scripting vulnerability in Webkul Qloapps 1.6.0 An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter. | 6.1 |
2023-05-27 | CVE-2023-2925 | Cross-site Scripting vulnerability in Webkul Krayin CRM 1.2.4 A vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. | 5.4 |
2023-05-11 | CVE-2023-30256 | Cross-site Scripting vulnerability in Webkul Qloapps 1.5.2 Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file. | 6.1 |
2022-06-21 | CVE-2021-41924 | Cross-site Scripting vulnerability in Webkul Krayin Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS). | 4.3 |