CRITICAL
9.8 CVE-2026-50769 Published 17 Aug 2026
CRM+ Appointments SQL Injection Vulnerability
Worried this affects one of your servers?
The CRM+ application from Brainformatik, version 2025.6 and earlier, is affected by a time-based SQL Injection vulnerability.
The flaw is in the calendar conflict-check endpoint index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=true.
- Affected versions: 2025.6 and earlier
- Impact: an attacker can execute arbitrary code
Reference: CVE-2026-50769 on NVD
← Back to Security News