Looking for the vulnerability index of Invicti's legacy products?

EspoCRM

EspoCRM is a web application that allows you to see enter and evaluate all your company relationships regardless of the type. People companies projects or opportunities all in an easy and intuitive interface.

Severity Summary:

Critical: 1 High: 5 Medium: 19
Reference
Title
Severity
EspoCRM Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Critical
EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability
High
EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability
High
EspoCRM Improper Restriction of Excessive Authentication Attempts Vulnerability
High
EspoCRM Improper Neutralization of Formula Elements in a CSV File Vulnerability
High
EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability
High
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Cleartext Transmission of Sensitive Information Vulnerability
Medium
EspoCRM Improper Neutralization of Formula Elements in a CSV File Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Permissions Privileges and Access Controls Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Server-Side Request Forgery (SSRF) Vulnerability
Medium