Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-37006

Опубликовано: 29 янв. 2026
Источник: nvd
CVSS3: 8.2
EPSS Низкий

Описание

berliCRM 1.0.24 contains a SQL injection vulnerability in the 'src_record' parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through a crafted POST request to the index.php endpoint to potentially extract or modify database information.

EPSS

Процентиль: 14%
0.00045
Низкий

8.2 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.2
github
9 дней назад

berliCRM 1.0.24 contains a SQL injection vulnerability in the 'src_record' parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through a crafted POST request to the index.php endpoint to potentially extract or modify database information.

EPSS

Процентиль: 14%
0.00045
Низкий

8.2 High

CVSS3

Дефекты

CWE-89