🔐 CVE Alert

CVE-2026-12260

UNKNOWN 0.0

SQL injection in the NetBoard CRM demo platform

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in the ‘/module/auth/recovery.php’ endpoint. The parameter is vulnerable to blind attacks based on Boolean, error, time-based and UNION techniques. Exploitation allows attackers to extract confidential information (such as the version and type of backend used), alter data or further compromise the CRM environment.

CWE CWE-89
Vendor netboard crm
Product netboard crm demo platform
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for netboard crm netboard crm demo platform

Be the first to know when new unknown vulnerabilities affecting netboard crm netboard crm demo platform are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

NetBoard CRM / NetBoard CRM Demo Platform
0 < 08/10/2026

References

NVD ↗ CVE.org ↗ EPSS Data ↗
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/sql-injection-netboard-crm-demo-platform

Credits

Gonzalo Aguilar García (6h4ack)