VYPR
High severity7.5NVD Advisory· Published Oct 29, 2021· Updated Jun 17, 2026

CVE-2021-41746

CVE-2021-41746

Description

SQL Injection vulnerability exists in all versions of Yonyou TurboCRM.via the orgcode parameter in changepswd.php. Attackers can use the vulnerabilities to obtain sensitive database information.

Affected products

2
  • Yonyou/TurboCRM2 versions
    cpe:2.3:a:yonyou:turbocrm:-:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:yonyou:turbocrm:-:*:*:*:*:*:*:*
    • (no CPE)

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.