Brightsuite · Brightsuite Groupware · CVE-2010-5008
**Name of the Vulnerable Software and Affected Versions**
BrightSuite Groupware version 5.4
**Description**
A SQL injection issue allows remote attackers to execute arbitrary SQL commands. The issue is exploited via the `ContactID` parameter in the "pages/contact list mail form.asp" page.
**Recommendations**
For BrightSuite Groupware version 5.4, update the software to a version that fixes this issue, or as a temporary workaround, consider restricting access to the "pages/contact list mail form.asp" page to minimize the risk of exploitation. Avoid using the `ContactID` parameter in the affected page until the issue is resolved.