vendor:
LeadPro CRM
by:
Ahmet Ümit BAYRAM
9.8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: LeadPro CRM
Affected Version From: LeadPro CRM v1.0
Affected Version To: LeadPro CRM v1.0
Patch Exists: NO
Related CWE:
CPE: a:codecanyon:leadifly_lead_call_center_crm:1.0
Platforms Tested: Kali Linux
2023
LeadPro CRM v1.0 – SQL Injection
The LeadPro CRM v1.0 is vulnerable to SQL Injection. An attacker can exploit this vulnerability to execute arbitrary SQL queries, which could result in unauthorized access to or modification of the database.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user inputs and use prepared statements or parameterized queries to prevent SQL Injection attacks. Regularly updating the software to the latest version is also advised.