CRITICAL
NetBoard CRM
CVE published 2026-10-08
CVE-2026-12260
A SQL injection vulnerability exists in the NetBoard CRM demo platform, specifically in the 'user-name' POST parameter of the '/module/auth/recovery.php' endpoint. This vulnerability allows for blind attacks using Boolean, error, time-based, and UNION techniques, potentially enabling attackers to extract confidential information, alter data, or further compromise the CRM environment.