ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-37006”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-37006
Published
2026-01-29
CVSS:
7.1
ShadowTrackr CVSS:
5.0
Summary:
berliCRM 1.0.24 contains a SQL injection vulnerability in the 'src_record' parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through a crafted POST request to the index.php endpoint to potentially extract or modify database information.