SQL injection vulnerability in _phenotype/admin/login.php in Phenotype CMS before 2.9 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka the login name).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 62.1%