CVE-2020-5292 | Leantime up to 2.0.14/2.1-beta2 searchUsers sql injection
A vulnerability classified as critical was found in Leantime up to 2.0.14/2.1-beta2. Affected by this vulnerability is an unknown functionality. The manipulation of the argument searchUsers as part of POST Request leads to sql injection.
This vulnerability is known as CVE-2020-5292. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.