Description
Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice endpoint. Attackers can exploit the lack of input sanitization or parameterization through UNION-based injection techniques to extract sensitive data from the underlying database. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18.
Published: 2026-09-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Immediate Patch
AI Analysis

Impact

Chanjet CRM is vulnerable to an unauthenticated SQL injection in the webservice endpoint get_usedspace.php, triggered by manipulating the site_id GET parameter. The application does not sanitize or parameterize this input, enabling attackers to construct UNION-based queries that read arbitrary data from the database. The vulnerability allows remote attackers to execute arbitrary SQL statements, potentially extracting sensitive data or compromising the entire database, as confirmed by evidence collected in October 2023.

Affected Systems

The affected product is Chanjet Information Technology Co., Ltd.’s CRM system. No specific product version information is provided, so all releases of the CRM containing the get_usedspace.php endpoint are potentially at risk.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity attack that can be performed from a remote source without authentication. The EPSS score is not available, but exploitation was observed in late 2023, suggesting real-world use. The vulnerability is not listed in the CISA KEV catalog, but the lack of authentication and the ability to inject arbitrary SQL queries make it highly exploitable via simple HTTP GET requests to an unprotected endpoint.

Generated by OpenCVE AI on September 19, 2026 at 10:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor-released patch or upgrade the Chanjet CRM to a version that fixes the SQL injection flaw.
  • If a patch is not yet available, restrict or block access to the get_usedspace.php endpoint through firewall or routing rules to only trusted IP addresses.
  • Deploy a web application firewall rule that blocks UNION-based and other suspicious SQL payloads from reaching the endpoint.
  • Conduct a full security assessment and code review to ensure all input parameters in the CRM are properly sanitized or parameterized.

Generated by OpenCVE AI on September 19, 2026 at 10:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Chanjet Information Technology
Chanjet Information Technology crm
Vendors & Products Chanjet Information Technology
Chanjet Information Technology crm

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice endpoint. Attackers can exploit the lack of input sanitization or parameterization through UNION-based injection techniques to extract sensitive data from the underlying database. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18.
Title Chanjet CRM SQL Injection via get_usedspace.php
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Chanjet Information Technology Crm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T18:28:12.645Z

Reserved: 2026-09-18T17:37:10.883Z

Link: CVE-2021-48008

cve-icon Vulnrichment

Updated: 2026-09-21T18:28:05.810Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T19:16:40.563

Modified: 2026-09-24T21:08:55.030

Link: CVE-2021-48008

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:03:52Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')