CRITICAL 9.8 CVE-2026-50769 Published 17 Aug 2026

CRM+ Appointments SQL Injection Vulnerability

Worried this affects one of your servers?

The CRM+ application from Brainformatik, version 2025.6 and earlier, is affected by a time-based SQL Injection vulnerability.

The flaw is in the calendar conflict-check endpoint index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=true.

  • Affected versions: 2025.6 and earlier
  • Impact: an attacker can execute arbitrary code

Reference: CVE-2026-50769 on NVD

← Back to Security News