Sceawere

Vulnerability Detail

CVE-2026-105288UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Reflected XSS in feelcrm-os

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
9h ago
Vendor
feelec-yishu
Product
feelcrm-os
Attack Type
Cross Site Scripting
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in feelec-yishu feelcrm-os 1.0.0. Affected by this vulnerability is the function IndexController::index of the file App/ThinkPHP/Common/functions.php of the component Crm Endpoint. Such manipulation of the argument redirect_url leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-05T10:16:41.713Z",
  "pubdate": "2026-10-05T10:16:41.713Z",
  "executiveSummary": "A reflected Cross-Site Scripting (XSS) vulnerability exists in feelec-yishu feelcrm-os version 1.0.0, specifically within the Crm Endpoint component.\nThe vulnerability arises due to improper neutralization of user-supplied input provided to the redirect_url parameter within the IndexController::index function.\nSuccessful exploitation allows a remote, unauthenticated attacker to execute arbitrary JavaScript code within the context of the victim's browser session.\nThe impact includes the potential for session hijacking, unauthorized actions performed on behalf of the user, theft of sensitive authentication cookies, or redirection to malicious third-party websites.\nThe vulnerability is currently publicly disclosed with an existing exploit, increasing the risk of active exploitation. The vendor has not yet addressed the report.",
  "technicalDetails": "The vulnerability is located in the App/ThinkPHP/Common/functions.php file, specifically within the IndexController::index function of the feelcrm-os Crm Endpoint.\nThe root cause is a failure to implement adequate input validation and output encoding on the 'redirect_url' parameter before it is reflected back to the client's browser.\nWhen a user accesses the affected endpoint with a maliciously crafted 'redirect_url' argument, the application embeds the input directly into the rendered HTML response without sanitization.\nAttack flow: An attacker crafts a URL containing a malicious payload (e.g., <script>alert(document.cookie)</script>) in the 'redirect_url' parameter. When a targeted user or administrator clicks on this link, the server processes the request and reflects the unsanitized payload into the response document.\nThe victim's browser interprets the injected payload as trusted code belonging to the origin of the application, thereby executing the script in the security context of the victim's session.\nAs the application utilizes the ThinkPHP framework, this flaw suggests a bypass or lack of built-in protective measures against reflective input processing in the specific controller logic.\nSince the vulnerability is exploitable remotely and does not require prior authentication, the attack surface is broad, allowing an attacker to craft links for phishing campaigns or social engineering attacks.\nPost-exploitation, an attacker can access session-specific data, modify the DOM to present deceptive content to the user, or capture sensitive keystrokes, leading to complete compromise of the user's interaction with the feelcrm-os platform."
}
CVE-2026-105288: Reflected XSS in feelcrm-os (MEDIUM Severity, CVSS: 4.3) | Sceawere