CVE-2020-10218: Sapplica Sentrifugo

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

A Blind SQL Injection issue was discovered in Sapplica Sentrifugo 3.2 via the index.php/holidaygroups/add id parameter because of the HolidaydatesController.php addAction function.

Affected products

Published 2020-03-13. Last modified 2026-06-17.