Sceawere
Vulnerability Detail
CVE-2026-105289UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
FeelCRM Stored Cross-Site Scripting
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.5
- Creation Date
- 8h ago
- Vendor
- feelec-yishu
- Product
- feelcrm-os
- Attack Type
- Cross Site Scripting
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was found in feelec-yishu feelcrm-os 1.0.0. Affected by this issue is the function htmlspecialchars_decode of the file App/Feelcrm/Common/Model/CrmDefineFormModel.class.php of the component Create Customer Endpoint. Performing a manipulation of the argument customer_form[remark] results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.5",
"pubDate": "2026-10-05T11:16:46.617Z",
"pubdate": "2026-10-05T11:16:46.617Z",
"executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists in the feelec-yishu feelcrm-os 1.0.0 software. The vulnerability resides within the Create Customer Endpoint, specifically affecting the handling of the 'customer_form[remark]' argument.\nThe flaw occurs because the application fails to adequately sanitize user-supplied input before rendering it in the browser, allowing for the injection and execution of arbitrary JavaScript.\nThis vulnerability is classified as an XSS issue, which can lead to unauthorized actions performed on behalf of legitimate users, potential session hijacking, and the theft of sensitive session tokens or cookies.\nThe vulnerability can be exploited remotely by an unauthenticated or authenticated attacker, depending on the exposure of the endpoint. As an exploit has been made public and the vendor has not responded to vulnerability disclosure, the risk to deployments of feelcrm-os 1.0.0 is significant.",
"technicalDetails": "The vulnerability is located in the file App/Feelcrm/Common/Model/CrmDefineFormModel.class.php within the Create Customer Endpoint component of feelcrm-os version 1.0.0.\nThe root cause is improper input validation and output encoding within the 'htmlspecialchars_decode' function processing logic. While the application attempts to decode HTML entities, it fails to perform adequate context-aware sanitization of the 'customer_form[remark]' input parameter before the data is processed or subsequently reflected to the user interface.\nThe attack flow begins when an attacker crafts a malicious payload containing JavaScript, such as '<script>alert(document.cookie)</script>', and submits it through the 'customer_form[remark]' field during the customer creation process.\nThe server processes this input, and due to the flaw in the CrmDefineFormModel.class.php logic, the malicious payload is stored in the database without being properly neutralized. When the application later retrieves this record and reflects it in the administrative dashboard or customer management interface, the browser interprets the payload as legitimate script code.\nBecause the payload is persisted on the server, this is a Stored XSS vulnerability. Any user, including administrators with higher privileges, who views the compromised customer record will execute the injected script within the context of their own session.\nThe execution of the script occurs within the victim's browser, granting the attacker the ability to bypass the same-origin policy, intercept sensitive cookies or session tokens, modify the Document Object Model (DOM) of the page, or perform unauthorized actions as the victim user.\nThe exploitation is trivial as it only requires the attacker to submit a standard HTTP POST request containing the malicious payload to the affected endpoint. As the vulnerability is remote and the exploit code is publicly available, the barrier to entry for potential attackers is extremely low."
}