ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-14472
Zurmo 3.2.7-2 has XSS via the app/index.php/zurmo/default PATH_INFO.

Zurmo 3.2.7-2 has XSS via the app/index.php/zurmo/default PATH_INFO.

NVD description · AI analysis pending
6.1<1% PoC
  • zurmo zurmo
CVE-2018-19596
+1 in the same advisory: …19506
Zurmo 3.2.4 allows HTML Injection via an admin's use of HTML in the report section, a related issue to CVE-2018-19506.

Zurmo 3.2.4 allows HTML Injection via an admin's use of HTML in the report section, a related issue to CVE-2018-19506.

NVD description · AI analysis pending
4.8<1%
  • zurmo zurmo
CVE-2018-16654
Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1.

Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1.

NVD description · AI analysis pending
6.1<1% PoC
  • zurmo zurmo crm
CVE-2017-18004
Zurmo 3.2.3 allows XSS via the latitude or longitude parameter to maps/default/mapAndPoint.

Zurmo 3.2.3 allows XSS via the latitude or longitude parameter to maps/default/mapAndPoint.

NVD description · AI analysis pending
5.4<1% PoC
  • zurmo zurmo crm
CVE-2017-16569
+1 in the same advisory: …15039
An Open URL Redirect issue exists in Zurmo 3.2.1.57987acc3018 via an http:

An Open URL Redirect issue exists in Zurmo 3.2.1.57987acc3018 via an http: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting.

NVD description · AI analysis pending
4.8<1%
  • zurmo zurmo crm
CVE-2017-7188
Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data:

Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse.

NVD description · AI analysis pending
5.41% PoC
  • zurmo zurmo crm