CVE-2026-50769: SQL Injection
The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conflict endpoint index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=true which is used to check any conflicts for user calendar is vulnerable to SQL injection allowing an attacker to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50769?
CVE-2026-50769 has a severity score of 85, indicating a critical risk level.
How do I fix CVE-2026-50769?
To fix CVE-2026-50769, upgrade to a version of Brainformatik CRM+ that is later than 2025.6.
What type of vulnerability is CVE-2026-50769?
CVE-2026-50769 is an SQL Injection vulnerability that can be exploited through the check conflict endpoint.
Which application is affected by CVE-2026-50769?
The application affected by CVE-2026-50769 is the Brainformatik CRM+ software prior to version 2025.6.
What is the exploit method for CVE-2026-50769?
CVE-2026-50769 can be exploited through a time-based SQL injection via the check conflict endpoint.