Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-v9fj-h8g6-4w9q: YetiForce CRM vulnerable to stored Cross-site Scripting

YetiForce CRM version 6.4.0 and prior is vulnerable to stored cross-site scripting. A patch is available on the developer branch.

ghsa
#xss#git

YetiForce CRM vulnerable to stored Cross-site Scripting

Moderate severity GitHub Reviewed Published Oct 6, 2022 • Updated Oct 6, 2022

Related news

CVE-2022-3002: Improved display of data in the business hours · YetiForceCompany/YetiForceCRM@54728be

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.