Impact
Chanjet CRM is vulnerable to an unauthenticated SQL injection in the webservice endpoint get_usedspace.php, triggered by manipulating the site_id GET parameter. The application does not sanitize or parameterize this input, enabling attackers to construct UNION-based queries that read arbitrary data from the database. The vulnerability allows remote attackers to execute arbitrary SQL statements, potentially extracting sensitive data or compromising the entire database, as confirmed by evidence collected in October 2023.
Affected Systems
The affected product is Chanjet Information Technology Co., Ltd.’s CRM system. No specific product version information is provided, so all releases of the CRM containing the get_usedspace.php endpoint are potentially at risk.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity attack that can be performed from a remote source without authentication. The EPSS score is not available, but exploitation was observed in late 2023, suggesting real-world use. The vulnerability is not listed in the CISA KEV catalog, but the lack of authentication and the ability to inject arbitrary SQL queries make it highly exploitable via simple HTTP GET requests to an unprotected endpoint.
OpenCVE Enrichment