Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-08153
HistoryJan 26, 2022 - 12:00 a.m.

YetiForceCrm Cross-site Request Forgery Vulnerability (CNVD-2022-08153)

2022-01-2600:00:00
China National Vulnerability Database
www.cnvd.org.cn
5
yetiforcecrm
cross-site request forgery
vulnerability
polish company
client-side data
javascript code

EPSS

0.001

Percentile

40.4%

YetiForceCrm is an open source Crm system from the Polish company YetiForce. YetiForceCrm version 6.3.0 previously contained a cross-site request forgery vulnerability, which stems from the lack of proper validation of client-side data by the WEB application. An attacker could exploit the vulnerability to execute JavaScript code on the client side.

EPSS

0.001

Percentile

40.4%