PT-2023-21313 · Unknown · Idurar Erp/Crm

G37Sys73M

+1

·

Published

2023-05-16

·

Updated

2025-01-23

·

CVE-2023-27742

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IDURAR ERP/CRM version 1
Description The issue is related to a SQL injection vulnerability. It affects the /api/login component.
Recommendations For IDURAR ERP/CRM version 1, consider restricting access to the /api/login endpoint until a patch is available. As a temporary workaround, avoid using sensitive data in the login functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-27742

Affected Products

Idurar Erp/Crm