Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Ultimate Project Manager CRM PRO 2.0.5 - SQLi Credentials Leakage
Vulnerability Description
Ultimate Project Manager CRM PRO 2.0.5 contains a blind SQL injection vulnerability that allows attackers to extract usernames and password hashes from the tbl_users database table. Attackers can exploit the /frontend/get_article_suggestion/ endpoint by crafting malicious search parameters to progressively guess and retrieve user credentials through boolean-based inference techniques.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
CodexCube Ultimate Project Manager CRM PRO SQL注入漏洞
Vulnerability Description
CodexCube Ultimate Project Manager CRM PRO是CodexCube公司的一个全流程业务管理平台。 CodexCube Ultimate Project Manager CRM PRO 2.0.5版本存在SQL注入漏洞,该漏洞源于/frontend/get_article_suggestion/端点存在盲SQL注入,可能导致提取用户凭据。
CVSS Information
N/A
Vulnerability Type
N/A