Sceawere
Vulnerability Detail
CVE-2026-105291UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Reflected XSS in feelcrm-os
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 8h ago
- Vendor
- feelec-yishu
- Product
- feelcrm-os
- Attack Type
- Cross Site Scripting
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function GroupController::index of the file App/Feelcrm/Index/Controller/GroupController.class.php of the component Department Search Endpoint. The manipulation of the argument keyword leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-05T11:16:46.983Z",
"pubdate": "2026-10-05T11:16:46.983Z",
"executiveSummary": "A reflected Cross-Site Scripting (XSS) vulnerability exists in feelec-yishu feelcrm-os 1.0.0 within the Department Search Endpoint.\nThe vulnerability is triggered via improper sanitization of the 'keyword' argument in the GroupController::index function.\nSuccessful exploitation allows remote attackers to execute arbitrary JavaScript in the context of the victim's browser session.\nThis can lead to unauthorized actions, session hijacking, or the exfiltration of sensitive information such as authentication cookies or CSRF tokens.\nThe flaw stems from the application's failure to properly encode user-supplied input before rendering it in the HTML response.\nThe issue is exacerbated by the availability of public exploits, increasing the risk of active exploitation by malicious actors.\nThe vendor has not yet addressed the report, leaving installations currently exposed to remote attack vectors without authentication requirements.",
"technicalDetails": "The vulnerability resides in the 'App/Feelcrm/Index/Controller/GroupController.class.php' file, specifically within the 'GroupController::index' method. The application utilizes the 'keyword' parameter to perform search operations across department records. It was identified that the application fails to perform adequate input validation or contextual output encoding when reflecting the 'keyword' parameter back into the HTML response document.\nExploitation is achieved through a reflected XSS vector. An attacker can craft a malicious URL containing a JavaScript payload within the 'keyword' argument. When a victim, such as an authenticated administrator or user, clicks on the crafted link, the server processes the request and embeds the unvalidated input directly into the rendered page.\nThe attack flow proceeds as follows: 1) The attacker constructs a malicious link targeting the vulnerable 'GroupController::index' endpoint. 2) The attacker lures a victim to visit this URL. 3) The 'GroupController' receives the request, takes the malicious payload from the 'keyword' parameter, and includes it within the HTTP response without proper character entity encoding (e.g., converting '<' to '<'). 4) The victim's browser interprets the injected script as legitimate code originating from the trusted domain of the feelcrm-os installation.\nBecause the payload executes within the victim's active session, the script inherits the session's privileges. This allows the attacker to perform actions on behalf of the user, bypass CSRF protections, or exfiltrate sensitive data stored in 'localStorage', 'sessionStorage', or non-HttpOnly cookies. The lack of Content Security Policy (CSP) headers in the application further facilitates the successful execution of arbitrary scripts.\nThis vulnerability is reachable remotely without requiring prior authentication, making it a critical threat to the security integrity of the application. The absence of a vendor-supplied patch necessitates manual intervention to mitigate the risk of exploitation."
}