CVE-2024-44541: Evilnapsis Inventio-Lite

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin."

Affected products

Published 2024-09-11. Last modified 2026-06-17.