plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in the username parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.085
EPSS Ranking 92.4%