CVE-2026-12260 | Demo Platform recovery.php user-name sql injection
A vulnerability labeled as critical has been found in Demo Platform. Affected by this issue is some unknown functionality of the file /module/auth/recovery.php. Executing a manipulation of the argument user-name can lead to sql injection.
This vulnerability is handled as CVE-2026-12260. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More