Sceawere
Vulnerability Detail
CVE-2026-105290UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SSRF in feelcrm-os GoogleController
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 8h ago
- Vendor
- feelec-yishu
- Product
- feelcrm-os
- Attack Type
- Server-Side Request Forgery
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in feelec-yishu feelcrm-os 1.0.0. This affects an unknown part of the file App/Feelcrm/Index/Controller/GoogleController.class.php of the component getCurlData Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-05T11:16:46.807Z",
"pubdate": "2026-10-05T11:16:46.807Z",
"executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability has been identified in feelec-yishu feelcrm-os version 1.0.0. The vulnerability resides within the getCurlData endpoint located in App/Feelcrm/Index/Controller/GoogleController.class.php.\nThe flaw allows an unauthenticated remote attacker to influence the 'url' argument, forcing the server to initiate arbitrary HTTP requests to internal or external resources.\nThis vulnerability poses a significant risk to the integrity and confidentiality of the internal network infrastructure. By leveraging the server as a proxy, an attacker can bypass firewalls, access internal services not exposed to the public internet, or perform port scanning and service discovery on the host's network segment.\nThe vulnerability is currently unpatched, and public exploit disclosures are available, increasing the potential for active exploitation. Remediation efforts should focus on strict input validation and service-level egress filtering.",
"technicalDetails": "The vulnerability originates from improper handling of user-supplied input within the getCurlData function inside the App/Feelcrm/Index/Controller/GoogleController.class.php file. The application accepts a 'url' parameter from the user, which is subsequently passed to a cURL-based request handler without adequate validation or sanitization.\nIn a typical attack flow, an attacker submits a crafted HTTP request containing the 'url' parameter set to a target URI of their choosing. The application then uses the server's internal context to fetch content from that URI. Because the server does not verify the destination, the attacker can specify internal IP addresses (e.g., 127.0.0.1 or 10.0.0.x), private subnets, or metadata services (such as AWS/GCP/Azure instance metadata endpoints).\nThe lack of a whitelist-based URL validation mechanism means that the application acts as a confused deputy. When the request is processed, the backend server executes the cURL operation, and the response is potentially returned to the attacker or causes the server to perform actions dictated by the remote target. This behavior facilitates the exploitation of internal services that rely on implicit trust based on network location, such as administrative panels, local databases, or Redis caches.\nExploitation is straightforward and does not require prior authentication. As the endpoint is reachable remotely, any external actor can trigger the request. The impact is significant: beyond simple information disclosure of internal resources, this SSRF can lead to full remote code execution if the application server can reach vulnerable internal services that permit authenticated actions without credentials or if the server's own configuration allows for protocol smuggling (e.g., using gopher:// or file:// if the underlying cURL installation supports them).\nGiven that the project has not responded to reported issues and no official security patch exists for version 1.0.0, the environment remains vulnerable. Attackers may combine this with other network-based vulnerabilities to pivot deep into the target's infrastructure, significantly escalating the breach's severity."
}