VTiger CRM <= 8.1.0 does not properly sanitize user input...
High severity
Unreviewed
Published
Aug 16, 2024
to the GitHub Advisory Database
•
Updated Aug 16, 2024
Description
Published by the National Vulnerability Database
Aug 16, 2024
Published to the GitHub Advisory Database
Aug 16, 2024
Last updated
Aug 16, 2024
VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module.
References