CVE-2020-13968: Crk Business Platform

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

CRK Business Platform <= 2019.1 allows can inject SQL statements against the DB on any path using the 'strSessao' parameter.

Affected products

  • Crk Business Platform: up to and including 2019.1

Published 2020-12-23. Last modified 2026-06-17.