Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hp7f-wr35-xpvj

Опубликовано: 29 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 8.2

Описание

berliCRM 1.0.24 contains a SQL injection vulnerability in the 'src_record' parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through a crafted POST request to the index.php endpoint to potentially extract or modify database information.

berliCRM 1.0.24 contains a SQL injection vulnerability in the 'src_record' parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through a crafted POST request to the index.php endpoint to potentially extract or modify database information.

EPSS

Процентиль: 16%
0.0005
Низкий

7.1 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.2
nvd
9 дней назад

berliCRM 1.0.24 contains a SQL injection vulnerability in the 'src_record' parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through a crafted POST request to the index.php endpoint to potentially extract or modify database information.

EPSS

Процентиль: 16%
0.0005
Низкий

7.1 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-89