CVE-2020-13968: Crk Business Platform
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
CRK Business Platform <= 2019.1 allows can inject SQL statements against the DB on any path using the 'strSessao' parameter.
Affected products
- Crk Business Platform: up to and including 2019.1
Published 2020-12-23. Last modified 2026-06-17.