CVE-2023-50035
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
29/12/2023
Last modified:
05/01/2024
Description
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is directly used in the SQL query without any sanitization and the SQL Injection payload being executed.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:small_crm_project:small_crm:3.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



