Realization · Realization Concerto Critical Chain Planner · CVE-2019-13027
**Name of the Vulnerable Software and Affected Versions**
Realization Concerto Critical Chain Planner (aka CCPM) version 5.10.8071
**Description**
The issue concerns a SQL Injection problem. It is located in the taskupdt/taskdetails.aspx webpage, specifically via the `projectname` parameter.
**Recommendations**
For version 5.10.8071, avoid using the `projectname` parameter in the taskupdt/taskdetails.aspx webpage until the issue is resolved.