CyberRota Analysis
AI-GeneratedThe CRM+ application, up to version 2025.6, is susceptible to a time-based SQL Injection vulnerability in the check conflict endpoint, which could allow attackers to execute arbitrary code. This poses a significant risk to the integrity and confidentiality of user data, making it critical for organizations using this application to prioritize remediation efforts. Users of the affected CRM+ version should urgently assess their exposure and implement necessary security measures.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conflict endpoint index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=true which is used to check any conflicts for user calendar is vulnerable to SQL injection allowing an attacker to execute arbitrary code.