CVE-2018-20508: Crashfix Project Crashfix
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
CrashFix 1.0.4 has SQL Injection via the User[status] parameter. This is related to actionIndex in UserController.php, and the protected\models\User.php search() function.
Affected products
- Crashfix Project Crashfix: version 1.0.4 only
Published 2018-12-27. Last modified 2026-06-17.