Sceawere

Vulnerability Detail

CVE-2026-105388UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in feelcrm-os Member

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
1h ago
Vendor
feelec-yishu
Product
feelcrm-os
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A weakness has been identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function index of the file App/Feelcrm/Index/Controller/MemberController.class.php of the component Member Endpoint. This manipulation of the argument group_id causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-05T20:17:10.393Z",
  "pubdate": "2026-10-05T20:17:10.393Z",
  "executiveSummary": "A critical SQL injection vulnerability exists in feelec-yishu feelcrm-os version 1.0.0, specifically within the Member endpoint.\nThe vulnerability originates from improper sanitization of the 'group_id' argument processed by the 'index' function in 'App/Feelcrm/Index/Controller/MemberController.class.php'.\nThis security flaw allows a remote, unauthenticated attacker to manipulate backend database queries, potentially leading to unauthorized data extraction, modification, or destruction.\nThe risk is significantly elevated due to the existence of publicly available exploit code, which lowers the barrier for exploitation by threat actors.\nThe vendor has not yet responded to disclosure efforts, leaving installations vulnerable to exploitation.\nImpacts include full database compromise, unauthorized access to sensitive CRM member data, and potentially full application takeover.",
  "technicalDetails": "The vulnerability is a classic SQL injection residing in the 'index' function of 'App/Feelcrm/Index/Controller/MemberController.class.php'.\nThe root cause is the failure of the application to properly validate, sanitize, or parameterize the 'group_id' input parameter before incorporating it into a database query string.\nIn the affected component, user-supplied input provided through the 'group_id' parameter is concatenated directly into SQL statements used to fetch member data.\nBecause the input is not treated as a data literal, an attacker can supply specially crafted SQL syntax to manipulate the structure of the original query.\nExploitation is initiated remotely and does not require prior authentication. An attacker sends a crafted HTTP request containing malicious SQL commands within the 'group_id' argument.\nFor example, an attacker could supply input such as '1 OR 1=1' or utilize UNION-based techniques to extract database contents.\nThe database engine executes the injected malicious instructions alongside the intended legitimate query.\nThis allows the attacker to bypass access controls, perform unauthorized read or write operations, and potentially dump the contents of the database.\nThe lack of prepared statements or an effective Object-Relational Mapping (ORM) abstraction layer that handles query parameterization safely is the technical oversight enabling this flaw.\nAs the exploit code is public, the attack flow is trivial, involving the injection of SQL payloads into the exposed HTTP parameter.\nThe post-exploitation impact includes the loss of confidentiality, integrity, and availability for the CRM's backend database, potentially compromising all stored member information."
}
CVE-2026-105388: SQL Injection in feelcrm-os Member (MEDIUM Severity, CVSS: 6.3) | Sceawere