Sceawere
Vulnerability Detail
CVE-2026-105388UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in feelcrm-os Member
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 1h ago
- Vendor
- feelec-yishu
- Product
- feelcrm-os
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A weakness has been identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function index of the file App/Feelcrm/Index/Controller/MemberController.class.php of the component Member Endpoint. This manipulation of the argument group_id causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-10-05T20:17:10.393Z",
"pubdate": "2026-10-05T20:17:10.393Z",
"executiveSummary": "A critical SQL injection vulnerability exists in feelec-yishu feelcrm-os version 1.0.0, specifically within the Member endpoint.\nThe vulnerability originates from improper sanitization of the 'group_id' argument processed by the 'index' function in 'App/Feelcrm/Index/Controller/MemberController.class.php'.\nThis security flaw allows a remote, unauthenticated attacker to manipulate backend database queries, potentially leading to unauthorized data extraction, modification, or destruction.\nThe risk is significantly elevated due to the existence of publicly available exploit code, which lowers the barrier for exploitation by threat actors.\nThe vendor has not yet responded to disclosure efforts, leaving installations vulnerable to exploitation.\nImpacts include full database compromise, unauthorized access to sensitive CRM member data, and potentially full application takeover.",
"technicalDetails": "The vulnerability is a classic SQL injection residing in the 'index' function of 'App/Feelcrm/Index/Controller/MemberController.class.php'.\nThe root cause is the failure of the application to properly validate, sanitize, or parameterize the 'group_id' input parameter before incorporating it into a database query string.\nIn the affected component, user-supplied input provided through the 'group_id' parameter is concatenated directly into SQL statements used to fetch member data.\nBecause the input is not treated as a data literal, an attacker can supply specially crafted SQL syntax to manipulate the structure of the original query.\nExploitation is initiated remotely and does not require prior authentication. An attacker sends a crafted HTTP request containing malicious SQL commands within the 'group_id' argument.\nFor example, an attacker could supply input such as '1 OR 1=1' or utilize UNION-based techniques to extract database contents.\nThe database engine executes the injected malicious instructions alongside the intended legitimate query.\nThis allows the attacker to bypass access controls, perform unauthorized read or write operations, and potentially dump the contents of the database.\nThe lack of prepared statements or an effective Object-Relational Mapping (ORM) abstraction layer that handles query parameterization safely is the technical oversight enabling this flaw.\nAs the exploit code is public, the attack flow is trivial, involving the injection of SQL payloads into the exposed HTTP parameter.\nThe post-exploitation impact includes the loss of confidentiality, integrity, and availability for the CRM's backend database, potentially compromising all stored member information."
}