Impact
The CRM+ application from Brainformatik before and including version 2025.6 contains a time‑based SQL injection flaw in the CheckConflictOfDates endpoint (index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=true). An attacker can craft a malicious request that is injected into the underlying SQL query, allowing execution of arbitrary SQL statements and potentially arbitrary application code. The vulnerability enables a complete compromise of the application’s data and logic integrity.
Affected Systems
Brainformatik CRM+ versions 2025.6 and earlier are affected. No specific vendor or sub‑product variations are listed beyond the CRM+ product itself.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Because the vulnerability is a classic SQL injection in a publicly reachable web endpoint, the attack vector is inferred to be a web request. Exploitation would require the attacker to send a crafted HTTP request with malicious SQL payload to the vulnerable endpoint. The CVSS score of 9.8 indicates a very high severity. Mitigation relies on patching or input sanitization.
OpenCVE Enrichment