← Back

Yellowbox Crm

yellowbox_crm

Vendor: Dimo Crm • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dimo Crm
1Yellowbox Crm
Jun 17, 2026
Jan 21, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An Arbitrary File Upload issue in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to deploy a new WebApp WAR file to the Tomcat server via Path Traversal, allowing remote code exe...Show more
An Arbitrary File Upload issue in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to deploy a new WebApp WAR file to the Tomcat server via Path Traversal, allowing remote code execution with SYSTEM privileges.Show less
1Dimo Crm
1Yellowbox Crm
Jun 17, 2026
Jan 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an unauthenticated user to download arbitrary files from the server.
1Dimo Crm
1Yellowbox Crm
Jun 17, 2026
Jan 21, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Path Traversal in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to browse the server filesystem.
1Dimo Crm
1Yellowbox Crm
Jun 17, 2026
Jan 21, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Incorrect Access Control in AfficheExplorateurParam() in DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to use administrative controllers.