In NavigateCMS version 2.9.4 and below, function in product.php is vulnerable to sql injection on parameter id through a post request, which results in arbitrary sql query execution in the backend database.
product.php
id
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-37476.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "2.9.4" } ] }, { "events": [ { "introduced": "0" }, { "last_affected": "a" } ] } ]