Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eron Software Wowwo CRM allows Blind SQL Injection. This issue affects Wowwo CRM. NOTE: The vendor did not inform about the completion of the fixing process within the specified time. The CVE will be updated when new information becomes available.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version
Credits
Hüseyin ÜZÜM
References
www.usom.gov.tr/bildirim/tr-25-0141
siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0141