Sceawere

Vulnerability Detail

CVE-2026-105287UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in feelcrm-os

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
9h ago
Vendor
feelec-yishu
Product
feelcrm-os
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpoint. This manipulation of the argument groups[] causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-05T10:16:41.490Z",
  "pubdate": "2026-10-05T10:16:41.490Z",
  "executiveSummary": "A critical SQL injection vulnerability has been identified in feelec-yishu feelcrm-os version 1.0.0. The vulnerability resides within the getMemberByGroups endpoint, specifically affecting the App/Feelcrm/Crm/Controller/AjaxRequestController.class.php file.\nThis flaw allows a remote, unauthenticated attacker to inject malicious SQL commands via the 'groups[]' parameter. Successful exploitation permits unauthorized interaction with the underlying database, potentially leading to data exfiltration, unauthorized modification, or full compromise of the backend database management system.\nThe vulnerability is currently unpatched, and public exploit code exists, elevating the risk profile for deployments using this software. Given the lack of response from the maintainers, users are advised to implement immediate compensating controls to restrict access to the affected endpoint.",
  "technicalDetails": "The vulnerability is classified as an improper neutralization of special elements used in an SQL command (SQL Injection). The root cause lies in the insufficient sanitization and validation of the 'groups[]' array parameter processed within the getMemberByGroups function in 'App/Feelcrm/Crm/Controller/AjaxRequestController.class.php'.\nIn this implementation, the input provided to the 'groups[]' argument is directly concatenated or improperly embedded into dynamic SQL queries executed by the application against the database. Because the application fails to utilize prepared statements or parameterized queries, the input is interpreted as part of the SQL command syntax rather than data.\nThe attack flow begins with a remote request targeted at the 'getMemberByGroups' endpoint. An adversary can provide a crafted payload within the 'groups[]' parameter. For example, by supplying input containing single quotes, SQL comment sequences (e.g., --, #), or UNION SELECT statements, an attacker can manipulate the query logic. The application processes this input, and the database engine executes the injected commands with the privileges of the application's database user.\nExploitation does not require prior authentication, making the endpoint highly exposed to remote threats. Since the application fails to perform strict type checking or character escaping on the array elements, the injection vector allows for blind or error-based SQL injection techniques. This enables attackers to map database structures, bypass application-level authentication, extract sensitive user information, or modify application data.\nThe scope of impact extends to the entire database connected to the feelcrm-os application. Post-exploitation impact may include the total loss of confidentiality, integrity, and availability of the CRM data. As the vulnerability is confirmed in version 1.0.0 and public proof-of-concept exploits exist, the barrier to entry for potential attackers is significantly lowered."
}
CVE-2026-105287: SQL Injection in feelcrm-os (MEDIUM Severity, CVSS: 6.3) | Sceawere