Filtered by vendor Ourenergy Subscriptions
Filtered by product Collectric Cmu Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2018-25379 1 Ourenergy 1 Collectric Cmu 2026-05-26 8.2 High
Collectric CMU 1.0 contains a boolean-based blind SQL injection vulnerability in the lang parameter that allows unauthenticated attackers to manipulate database queries during authentication. Attackers can inject SQL code through the lang parameter in login requests to extract sensitive information from the database using time-based blind techniques.