CVE-2020-37033: Insite Software Infor StoreFront b2b
High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.
Infor Storefront B2B 1.0 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'usr_name' parameter in login requests. Attackers can exploit the vulnerability by injecting malicious SQL code into the 'usr_name' parameter to potentially extract or modify database information.
Affected products
- Insite Software Infor StoreFront b2b: version 1.0 only
Published 2026-01-30. Last modified 2026-06-17.