vendor:
Rukovoditel Project Management CRM
by:
Mehmet EMIROGLU
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Rukovoditel Project Management CRM
Affected Version From: 2.4.2001
Affected Version To: 2.4.2001
Patch Exists: NO
Related CWE:
CPE: a:rukovoditel_project_management_crm:rukovoditel:2.4.1
Platforms Tested: Windows
2019
Rukovoditel Project Management CRM 2.4.1 – ‘lists_id’ SQL Injection
The SQL injection vulnerability exists in Rukovoditel Project Management CRM 2.4.1. It can be exploited by a logged-in user through the global list tab by creating a new list and applying SQL injection.
Mitigation:
The vendor should release a patch to fix the SQL injection vulnerability. In the meantime, users should avoid using the affected feature or implement input validation and parameterized queries to prevent SQL injection.