QSearchQSearch

CVE-2021-41746

7.5 HIGH

SQL Injection vulnerability exists in all versions of Yonyou TurboCRM.via the orgcode parameter in changepswd.php

Published: 2021-10-29 · Last updated: 2026-06-17

Severity and scoring

CVSS
7.5 HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE
CWE-89

Affected products

VendorProduct
yonyouturbocrm

Description

SQL Injection vulnerability exists in all versions of Yonyou TurboCRM.via the orgcode parameter in changepswd.php. Attackers can use the vulnerabilities to obtain sensitive database information.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2021-41744 All versions of yongyou PLM are affected by a command injection issue (9.8 CRITICAL)

Same CWE

  • CVE-2026-52715 Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions (9.3 CRITICAL)
  • CVE-2026-52712 Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions (7.6 HIGH)
  • CVE-2026-49772 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events C... (9.3 CRITICAL)
  • CVE-2026-39581 Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions (8.5 HIGH)
  • CVE-2026-39574 Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions (9.3 CRITICAL)