IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login.
IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login.
SQL Injection
IDURAR ERP/CRM v1
https://github.com/idurar/erp-crm - version 1
Remote
true
Use the expression {"$ne":null} in the email keypair in the /api/login request
Soummya Mukhopadhyay @G37SYS73M