Security Advisory

CVE-2020-37004

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-29 14:28:28
Last updated 2026-05-26 11:51:39
Assigner VulnCheck
State PUBLISHED

Description

The Ultimate Project Manager CRM PRO version 2.0.5 contains a blind SQL injection vulnerability that allows attackers to extract usernames and password hashes from the tbl_users database table. Attackers can exploit the /frontend/get_article_suggestion/ endpoint by crafting malicious search parameters to progressively guess and retrieve user credentials through boolean-based inference techniques.