Impact
Uncontrolled redirect_url input in the IndexController::index function of the Crm Endpoint component permits injection of arbitrary script that will be executed in the victim's browser. The resulting client‑side compromise can expose session data, deface pages, or conduct phishing attacks. This weakness is linked to CWE‑79 and CWE‑94.
Affected Systems
The vulnerability affects feelec‑yishu feelcrm‑os version 1.0.0, particularly the file App/ThinkPHP/Common/functions.php used by the Crm Endpoint controller.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity, and the vulnerability is not listed in the CISA KEV catalog. EPSS data is not available, but the attack can be carried out remotely by tampering with the redirect_url request parameter to leak or manipulate client‑side data.
OpenCVE Enrichment