SQL injection in the NetBoard CRM demo platform

Posted date 08/10/2026
Identificador
INCIBE-2026-719
Importance
5 - Critical
Affected Resources

NetBoard CRM Demo Platform. Latest demo version (November 2025).

Description

INCIBE has coordinated the disclosure of a critical severity vulnerability affecting the NetBoard CRM demonstration platform, an interactive testing environment for business software. The vulnerability was discovered by Gonzalo Aguilar García (6h4ack).

This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:

  • CVE-2026-12260: CVSS v4.0: 10 | CVSS AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L | CWE-89
Solution

No solution has been reported as yet.

Detail

CVE-2026-12260: SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in the ‘/module/auth/recovery.php’ endpoint. The parameter is vulnerable to blind attacks based on Boolean, error, time-based and UNION techniques. Exploitation allows attackers to extract confidential information (such as the version and type of backend used), alter data or further compromise the CRM environment.

CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2026-12260 Crítica No NETBOARD CRM
References list