CVE-2022-1411
Estado: ModificadaMedia (6.1)—
Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.76%
- Percentil entre todas las CVEs puntuadas: 54
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-434
- CWE-434
Referencias
- https://github.com/yetiforcecompany/yetiforcecrm/commit/bf69c427260011ffca42f7b6935bb54080c54124
- https://huntr.dev/bounties/75c7cf09-d118-4f91-9686-22b142772529
- https://github.com/yetiforcecompany/yetiforcecrm/commit/bf69c427260011ffca42f7b6935bb54080c54124
- https://huntr.dev/bounties/75c7cf09-d118-4f91-9686-22b142772529
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-1411",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "security@huntr.dev",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 5.3,
"exploitabilityScore": 3.1
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@huntr.dev",
"affectedData": [
{
"vendor": "yetiforcecompany",
"product": "yetiforcecompany/yetiforcecrm",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "6.4.0",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-05-05T11:15:08.047",
"references": [
{
"url": "https://github.com/yetiforcecompany/yetiforcecrm/commit/bf69c427260011ffca42f7b6935bb54080c54124",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security@huntr.dev"
},
{
"url": "https://huntr.dev/bounties/75c7cf09-d118-4f91-9686-22b142772529",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "security@huntr.dev"
},
{
"url": "https://github.com/yetiforcecompany/yetiforcecrm/commit/bf69c427260011ffca42f7b6935bb54080c54124",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://huntr.dev/bounties/75c7cf09-d118-4f91-9686-22b142772529",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@huntr.dev",
"description": [
{
"lang": "en",
"value": "CWE-434"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-434"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover."
},
{
"lang": "es",
"value": "Una subida de archivos sin reestructurar en el repositorio de GitHub yetiforcecompany/yetiforcecrm versiones anteriores a 6.4.0. El atacante puede enviar archivos maliciosos a las víctimas es capaz de recuperar los datos almacenados de la aplicación web sin que esos datos se hagan seguros para renderizar en el navegador y roba la cookie de la víctima, conlleva a una toma de la cuenta"
}
],
"lastModified": "2026-06-17T04:22:24.210",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:yetiforce:yetiforce_customer_relationship_management:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "73B90905-4F4C-4C18-809E-376665A41EAD",
"versionEndExcluding": "6.4.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@huntr.dev"
}