CVE-2014-5521 | XRMS CRM 1.99.2 fingeruser.php Username sql injection (ID 128030 / EDB-34452)
A vulnerability classified as critical was found in XRMS CRM 1.99.2. Affected by this vulnerability is an unknown functionality of the file plugins/useradmin/fingeruser.php. The manipulation of the argument Username leads to sql injection.
This vulnerability is known as CVE-2014-5521. The attack can be launched remotely. Furthermore, there is an exploit available.