The Fhcrm Project maintains a healthcare customer relationship management application with a focused product footprint, presenting a relatively niche but specialized attack surface within the healthcare IT sector. The durable signal centers on SQL injection weaknesses in the platform's data-handling layer, reflecting common input-validation challenges in web-based database applications serving clinical environments. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fhcrm Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16353CRITICAL An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the /index.php/Customer/read limit parameter. | Sep 2, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-16354CRITICAL An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the index.php/User/read limit parameter. | Sep 2, 2018 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fhcrm Project.
Media articles that mention a CVE ID that affects a product developed by Fhcrm Project — matched by CVE ID, not by vendor name.