ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-14398
+3 in the same advisory: …9283 …14397 …14396
An issue was discovered in Creme CRM 1.6.12.

An issue was discovered in Creme CRM 1.6.12. The value of the cancel button uses the content of the HTTP Referer header, and could be used to trick a user into visiting a fake login page in order to steal credentials.

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • cremecrm cremecrm