CVE-2018-20508: Crashfix Project Crashfix

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

CrashFix 1.0.4 has SQL Injection via the User[status] parameter. This is related to actionIndex in UserController.php, and the protected\models\User.php search() function.

Affected products

Published 2018-12-27. Last modified 2026-06-17.