RULE(RULE ID:338227)

Rule General Information
Release Date: 2024-07-02
Rule Name: ENTER Customer Resource Management System Quotegask_editAction SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: The ENTER Customer Resource Management System is a professional customer relationship management (CRM) platform designed to help enterprises efficiently manage customer information, track sales opportunities and improve customer service quality. There is a SQL injection vulnerability in the Quotegask_editAction of ENTER Customer Resource Management System. An attacker can use this vulnerability to send malicious SQL code to the database, which may lead to data disclosure, data damage, service interruption and even complete control of the database server.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.