Sceawere
Vulnerability Detail
CVE-2026-105389UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unrestricted File Upload in feelcrm-os
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 2h ago
- Vendor
- feelec-yishu
- Product
- feelcrm-os
- Attack Type
- Unrestricted Upload
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security vulnerability has been detected in feelec-yishu feelcrm-os 1.0.0. This issue affects some unknown processing of the file App/Feelcrm/Crm/Controller/UploadController.class.php of the component UploadTicketFile Endpoint. Such manipulation of the argument cmd leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-10-05T20:17:10.610Z",
"pubdate": "2026-10-05T20:17:10.610Z",
"executiveSummary": "A critical security vulnerability has been identified in feelec-yishu feelcrm-os version 1.0.0, specifically within the UploadTicketFile endpoint.\nThe vulnerability is classified as an Unrestricted File Upload, which allows remote attackers to bypass security controls and upload arbitrary files to the server.\nThis flaw presents a severe risk as it may facilitate remote code execution (RCE) if the uploaded files are executed by the web server.\nThe attack is remotely exploitable, requiring no specific local access, and the availability of public exploit material increases the likelihood of active exploitation.\nThe lack of vendor response to early reports leaves the system exposed, as there is currently no official patch available to remediate this vulnerability.",
"technicalDetails": "The vulnerability resides in the UploadController.class.php file, specifically within the logic processing the UploadTicketFile endpoint. The application fails to adequately validate or sanitize the input provided through the 'cmd' argument during the file upload process.\nThe root cause is the absence of comprehensive server-side file type validation and filename sanitization. By manipulating the 'cmd' parameter, an attacker can influence the file handling logic, effectively bypassing standard extension filtering or directory traversal protections intended to restrict file uploads.\nThe attack flow initiates with a crafted HTTP request targeting the UploadTicketFile endpoint. The attacker leverages the insecure handling of the 'cmd' argument to bypass the application's intended upload constraints. Because the application does not enforce rigorous checks on the MIME type, file extension, or the destination path, an attacker can upload malicious scripts, such as PHP web shells, directly to an accessible web directory.\nOnce the file is uploaded, the attacker can execute the payload by navigating to the file's URL path. The web server interprets the uploaded script, granting the attacker arbitrary code execution privileges on the underlying host. The impact of this post-exploitation behavior is total compromise of the application, potential access to sensitive data, and complete control over the web server environment.\nThe vulnerability is present in version 1.0.0 of feelcrm-os. Exploitation does not appear to require complex authentication, and the nature of the endpoint suggests network-wide exposure, allowing any remote actor with access to the web interface to trigger the vulnerability. The publicly disclosed exploit code further facilitates the automated weaponization of this flaw, making it a high-priority target for threat actors.\nGiven that the project maintainers have not addressed the issue, there is no vendor-provided update to mitigate the risk. Security teams should assume that any file uploaded through this component is potentially malicious and should proactively implement restrictive measures to prevent unauthorized write operations to the web document root."
}