{"id":"CVE-2026-12260","title":"SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in the ‘/module/auth/recovery.php’ endpoint","summary":"SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in the ‘/module/auth/recovery.php’ endpoint. The parameter is vulnerable to blind attacks based on Boolean, error, …","severity":"critical","cvss":10,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L","cwe":["CWE-89"],"vendor":"NetBoard CRM","product":"NetBoard CRM Demo Platform","affected":["demo_platform < 08/10/2026"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T09:16:41.087","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-12260","references":[{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/sql-injection-netboard-crm-demo-platform","label":"cve-coordination@incibe.es"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-08T09:24:18.024Z","slug":"CVE-2026-12260","body":"## Overview\n\nSQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in the ‘/module/auth/recovery.php’ endpoint. The parameter is vulnerable to blind attacks based on Boolean, error, time-based and UNION techniques. Exploitation allows attackers to extract confidential information (such as the version and type of backend used), alter data or further compromise the CRM environment.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":55,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}