CVE-2026-72510

CRITICAL

The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection.