Dimo CRM maintains a focused customer-relationship-management product offering centered around its YellowBox CRM application. Current vulnerability severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dimo Crm over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14768HIGH An Arbitrary File Upload issue in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to deploy a new WebApp WAR file to the Tomcat server via | Jan 21, 2020 | 8.8 | 26 | NO | NO |
CVE-2019-14765HIGH Incorrect Access Control in AfficheExplorateurParam() in DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to use administrative controllers. | Jan 21, 2020 | 8.8 | 25 | NO | NO |
CVE-2019-14767HIGH In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an unauthenticated user to download arbitrary | Jan 21, 2020 | 7.5 | 22 | NO | NO |
CVE-2019-14766MEDIUM Path Traversal in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to browse the server filesystem. | Jan 21, 2020 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dimo Crm.
Media articles that mention a CVE ID that affects a product developed by Dimo Crm — matched by CVE ID, not by vendor name.