In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a password has been changed by the use…
In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CSTI). A low privileged attacker…
In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled…
In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his…
In Daybyday CRM, version 2.2.0 is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability that allows low privileged application users to store…
Daybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen.
Daybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen.
Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Project screen.
Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Lead screen.