Ultimate Project Manager CRM PRO Blind SQL Injection Vulnerability Allowing Credentials Leakage

Vulnerability

A blind SQL injection vulnerability has been identified in Ultimate Project Manager CRM PRO version 2.0.5. This vulnerability allows attackers to extract usernames and password hashes from the 'tbl_users' database table. Exploitation occurs through the '/frontend/get_article_suggestion/' endpoint, where malicious search parameters can be crafted to progressively guess and retrieve user credentials using boolean-based inference techniques.

Impact

Exploitation of this vulnerability leads to unauthorized access to user credentials, including usernames and password hashes.

Reproduction

The vulnerability can be reproduced by sending a POST request to the '/frontend/get_article_suggestion/' endpoint with a crafted 'search' parameter. The payload should be designed to exploit the SQL injection vulnerability by injecting SQL code that manipulates the query execution. The injection can be performed by guessing usernames and retrieving corresponding password hashes from the 'tbl_users' table.

Added: Jan 29, 2026, 3:48 PM
Updated: Jan 29, 2026, 5:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
2.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.