SQL injection in the NetBoard CRM demo platform
NetBoard CRM Demo Platform. Latest demo version (November 2025).
INCIBE has coordinated the disclosure of a critical severity vulnerability affecting the NetBoard CRM demonstration platform, an interactive testing environment for business software. The vulnerability was discovered by Gonzalo Aguilar García (6h4ack).
This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:
- CVE-2026-12260: CVSS v4.0: 10 | CVSS AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L | CWE-89
No solution has been reported as yet.
CVE-2026-12260: SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in the ‘/module/auth/recovery.php’ endpoint. The parameter is vulnerable to blind attacks based on Boolean, error, time-based and UNION techniques. Exploitation allows attackers to extract confidential information (such as the version and type of backend used), alter data or further compromise the CRM environment.
| Identificador CVE | Severidad | Explotación | Fabricante |
|---|---|---|---|
| CVE-2026-12260 | Crítica | No | NETBOARD CRM |


