CVE-2023-50035

CRITICAL WAF: High
CVSS 9.8 Published: 2023-12-29
CWE-89

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is directly used in the SQL query without any sanitization and the SQL Injection payload being executed.

WAF Coverage Analysis

SQL Injection High WAF Coverage

OWASP: A03:2021 Injection

942xxx - SQL Injection

Affected Software

VendorProductVersion
small_crm_projectsmall_crm3.0

References

  • github.com (Exploit, Mitigation, Third Party Advisory)
Back to CVE Database