Description
Ultimate Project Manager CRM PRO 2.0.5 contains a blind SQL injection vulnerability that allows attackers to extract usernames and password hashes from the tbl_users database table. Attackers can exploit the /frontend/get_article_suggestion/ endpoint by crafting malicious search parameters to progressively guess and retrieve user credentials through boolean-based inference techniques.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
nag0mez
References
www.exploit-db.com/exploits/48912 (ExploitDB-48912)
ultimatepro.codexcube.com/ (Ultimate Project Manager CRM PRO Vendor Homepage)
www.vulncheck.com/...anager-crm-pro-sqli-credentials-leakage (VulnCheck Advisory: Ultimate Project Manager CRM PRO 2.0.5 - SQLi Credentials Leakage)