Ultimate Project Manager CRM PRO 2.0.5 contains a blind...
High severity
Unreviewed
Published
Jan 29, 2026
to the GitHub Advisory Database
•
Updated Jan 29, 2026
Description
Published by the National Vulnerability Database
Jan 29, 2026
Published to the GitHub Advisory Database
Jan 29, 2026
Last updated
Jan 29, 2026
Ultimate Project Manager CRM PRO 2.0.5 contains a blind SQL injection vulnerability that allows attackers to extract usernames and password hashes from the tbl_users database table. Attackers can exploit the /frontend/get_article_suggestion/ endpoint by crafting malicious search parameters to progressively guess and retrieve user credentials through boolean-based inference techniques.
References