Impact
A flaw has been identified in the getMemberByGroups endpoint of the feelcrm-os application, where manipulation of the groups[] parameter allows attackers to inject arbitrary SQL statements. This vulnerability can enable unauthorized read or modification of the database, potentially exposing sensitive customer data or altering operational content. The weakness corresponds to input handling problems (CWE-74) and unsanitized SQL generation (CWE-89).
Affected Systems
The affected vendor is feelec‑yishu and the product is feelcrm‑os, specifically version 1.0.0. No other versions or distributions are listed as impacted, so the risk primarily applies to installations of that exact release.
Risk and Exploitability
The CVSS score of 5.3 places this issue in the medium severity range, reflecting that remote exploitation is possible but does not automatically provide full control of the system. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. However, the description notes that an exploit has been published and can operate remotely via Ajax requests to the vulnerable endpoint. Attackers would need network access to the application and the ability to craft HTTP requests with a malicious groups[] payload. The absence of an official fix means the risk remains unchanged unless mitigated through other means.
OpenCVE Enrichment