CVE-2020-37006: CRM-Now GmbH Berlicrm

High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.

berliCRM 1.0.24 contains a SQL injection vulnerability in the 'src_record' parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through a crafted POST request to the index.php endpoint to potentially extract or modify database information.

Affected products

Published 2026-01-29. Last modified 2026-06-17.