vendor:
Simple CRM
by:
Rinku Kumar (rinku191)
9,8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Simple CRM
Affected Version From: 3.0
Affected Version To: 3.0
Patch Exists: NO
Related CWE: N/A
CPE: a:phpgurukul:simple_crm:3.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Apache2+MariaDB
2021
Simple CRM 3.0 – ’email’ SQL injection (Authentication Bypass)
Simple CRM suffers from SQL injection vulnerability, allowing an un-authenticated attackers to login into CRM admin panel.
Mitigation:
Input validation and sanitization should be done to prevent SQL injection attacks.