Known Vulnerabilities for Daybyday by Daybydaycrm
Listed below are 6 of the newest known vulnerabilities associated with "Daybyday" by "Daybydaycrm".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-22113 json | In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a password has... | 8.8 - HIGH | 2022-01-13 | 2022-02-25 |
| CVE-2022-22112 json | In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CSTI). A... | 5.4 - MEDIUM | 2022-01-13 | 2022-01-20 |
| CVE-2020-35707 json | Daybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen. | 5.4 - MEDIUM | 2020-12-25 | 2020-12-28 |
| CVE-2020-35706 json | Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Project screen. | 5.4 - MEDIUM | 2020-12-25 | 2020-12-28 |
| CVE-2020-35705 json | Daybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen. | 5.4 - MEDIUM | 2020-12-25 | 2020-12-28 |
| CVE-2020-35704 json | Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Lead screen. | 5.4 - MEDIUM | 2020-12-25 | 2020-12-28 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Daybydaycrm | Daybyday | 2.1.0 |