Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-52470: Crocus v.1.3.44 Privilege Escalation via XML File

CVE-2026-52470 CVE-2026-52470
Summary

A security issue in Crocus v.1.3.44 allows an attacker to gain unauthorized access to sensitive data by manipulating the RecordStateMapper.xml file. This could lead to unauthorized changes to data or system compromise. Update to the latest version of Crocus to fix this issue.

Original title
SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file
Original description
SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file
Vulnerability type
CWE-89 SQL Injection
Published: 21 Jul 2026 · Updated: 23 Jul 2026 · First seen: 21 Jul 2026