Impact
The CRM+ application from Brainformatik before and including version 2025.6 contains a time‑based SQL injection flaw in the CheckConflictOfDates endpoint (index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=true). An attacker can craft a malicious request that is injected into the underlying SQL query, allowing execution of arbitrary SQL statements and potentially arbitrary application code if the database user has elevated privileges. The vulnerability enables a complete compromise of the application’s data and logic integrity.
Affected Systems
Brainformatik CRM+ versions 2025.6 and earlier are affected. No specific vendor or sub‑product variations are listed beyond the CRM+ product itself.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Because the vulnerability is a classic SQL injection in a publicly reachable web endpoint, the attack vector is inferred to be a web request. Exploitation would require the attacker to send a crafted HTTP request with malicious SQL payload to the vulnerable endpoint. No CVSS score is provided in the data. Mitigation relies on patching or input sanitization.
OpenCVE Enrichment