SQL Injection Vulnerability in NetBoard CRM by INCE
CVE-2026-12260

10CRITICAL

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-12260?

The NetBoard CRM demo platform is susceptible to an SQL injection vulnerability, specifically through the 'user-name' POST parameter in the '/module/auth/recovery.php' endpoint. This vulnerability allows attackers to perform blind SQL injection attacks, leveraging Boolean, error, time-based, and UNION techniques. Successful exploitation can lead to the unauthorized extraction of sensitive information, such as the backend version and type, the alteration of existing data, or further compromises within the CRM environment.

Affected Version(s)

NetBoard CRM Demo Platform 0 < 08/10/2026

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gonzalo Aguilar GarcĂ­a (6h4ack)
.