Tomikun2/SQL-Injection-in-CordysCRM

Tomikun2/SQL-Injection-in-CordysCRM

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.