CVE-2020-10218: Sapplica Sentrifugo
Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.
A Blind SQL Injection issue was discovered in Sapplica Sentrifugo 3.2 via the index.php/holidaygroups/add id parameter because of the HolidaydatesController.php addAction function.
Affected products
- Sapplica Sentrifugo: version 3.2 only
Published 2020-03-13. Last modified 2026-06-17.