PT-2022-24978 · Unknown · Tholum Crm42
Ace
·
Published
2022-11-11
·
Updated
2022-11-16
·
CVE-2022-3955
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
tholum crm42 (affected versions not specified)
Description
A critical issue affects the Login component of tholum crm42, specifically in the file crm42classclass.user.php. The manipulation of the
user name argument leads to SQL injection. This issue can be exploited remotely.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Neutralization
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tholum Crm42