cve/2024/CVE-2024-42994.md
2024-08-17 18:41:15 +00:00

666 B

CVE-2024-42994

Description

VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module.

POC

Reference

Github

No PoCs found on GitHub currently.