CVE-2026-2235: Hgiga C&cm@il Package Olln-Base

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

Affected products

  • Hgiga C&cm@il Package Olln-Base: before 7.0-978 (fixed in 7.0-978)

Published 2026-02-09. Last modified 2026-06-17.