Junglewise Threat Intelligence

CVE-2024-12150: Eron Software Wowwo CRM blind SQL injection

CVE-2024-12150 · Severity: critical · CVSS 9.8 · Published 2025-06-27

Executive brief

Eron Software's Wowwo CRM, a platform used for managing customer relationships and business operations, contains a critical security vulnerability. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive customer data or a complete takeover of the system. As of the latest report, the vendor has not confirmed a fix, posing a significant risk to organizations using this software.

Technical details

A blind SQL injection vulnerability (CWE-89) exists in Eron Software Wowwo CRM due to improper neutralization of special elements used in SQL commands. The flaw allows a remote, unauthenticated attacker to send crafted network requests to the application and infer data from the database based on the application's response patterns. With a CVSS score of 9.8, the vulnerability allows for full compromise of confidentiality, integrity, and availability. The vendor was notified but did not provide information regarding a patch within the required timeframe.

Affected products

  • Eron Software Wowwo CRM

Timeline

  • 2025-06-27: disclosed: Initial disclosure by TR-CERT (USOM)
  • 2025-06-27: advisory: CVE-2024-12150 published

References