Description
A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpoint. This manipulation of the argument groups[] causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-10-05
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL injection that can lead to data compromise
Action: Patch
AI Analysis

Impact

A flaw has been identified in the getMemberByGroups endpoint of the feelcrm-os application, where manipulation of the groups[] parameter allows attackers to inject arbitrary SQL statements. This vulnerability can enable unauthorized read or modification of the database, potentially exposing sensitive customer data or altering operational content. The weakness corresponds to input handling problems (CWE-74) and unsanitized SQL generation (CWE-89).

Affected Systems

The affected vendor is feelec‑yishu and the product is feelcrm‑os, specifically version 1.0.0. No other versions or distributions are listed as impacted, so the risk primarily applies to installations of that exact release.

Risk and Exploitability

The CVSS score of 5.3 places this issue in the medium severity range, reflecting that remote exploitation is possible but does not automatically provide full control of the system. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. However, the description notes that an exploit has been published and can operate remotely via Ajax requests to the vulnerable endpoint. Attackers would need network access to the application and the ability to craft HTTP requests with a malicious groups[] payload. The absence of an official fix means the risk remains unchanged unless mitigated through other means.

Generated by OpenCVE AI on October 5, 2026 at 11:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Contact the vendor feelec‑yishu and request a patch or update for feelcrm‑os 1.0.0
  • Implement server‑side validation to ensure that values passed in the groups[] parameter are properly escaped or parameterized before inclusion in SQL statements
  • Deploy a Web Application Firewall (WAF) or similar filtering tool to detect and block SQL injection attempts aimed at the getMemberByGroups endpoint

Generated by OpenCVE AI on October 5, 2026 at 11:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 10:00:00 +0000

Type Values Removed Values Added
Description A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpoint. This manipulation of the argument groups[] causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title feelec-yishu feelcrm-os getMemberByGroups Endpoint AjaxRequestController.class.php sql injection
First Time appeared Feelec-yishu
Feelec-yishu feelcrm-os
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:feelec-yishu:feelcrm-os:*:*:*:*:*:*:*:*
Vendors & Products Feelec-yishu
Feelec-yishu feelcrm-os
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Feelec-yishu Feelcrm-os
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T11:56:26.390Z

Reserved: 2026-10-04T22:44:13.989Z

Link: CVE-2026-105287

cve-icon Vulnrichment

Updated: 2026-10-05T11:56:22.519Z

cve-icon NVD

Status : Received

Published: 2026-10-05T10:16:41.490

Modified: 2026-10-05T12:17:09.180

Link: CVE-2026-105287

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T11:30:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')