Unknown · Finder Erp/Crm · CVE-2024-12144
**Name of the Vulnerable Software and Affected Versions**
Finder ERP/CRM (Old System) versions prior to 18.12.2024
**Description**
The issue is related to an SQL Injection vulnerability due to improper neutralization of special elements used in an SQL command. This allows for SQL Injection attacks.
**Recommendations**
For versions prior to 18.12.2024, update to a version released after 18.12.2024 to resolve the issue. As a temporary workaround, consider restricting access to sensitive database operations to minimize the risk of exploitation.