Impact
A cross‑site scripting flaw exists in the create‑customer endpoint of the feelcrm-os application. The vulnerability occurs when user supplied data in the customer_form[remark] field is processed by the library function htmlspecialchars_decode before being rendered on a webpage. Because the input is not properly sanitized or encoded, an attacker can inject arbitrary HTML or JavaScript that will be executed in the context of other users who view the remark. The flaw provides a path for information disclosure, defacement, or cookie theft and is classified as an input validation weakness (CWE‑79) and a context‑dependent code execution issue (CWE‑94).
Affected Systems
The affected product is feelcrm‑os, version 1.0.0, developed by feelec‑yishu. The vulnerability resides in the file CrmDefineFormModel.class.php within the App/Feelcrm/Common/Model directory of this release. CPE entry cpe:2.3:a:feelec‑yishu:feelcrm‑os:*:*:*:*:*:*:*:* captures the affected platform.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. EPSS for this vulnerability is not available, so the current exploitation probability cannot be quantified. The flaw is currently not listed in the CISA KEV catalog. The exploit is publicly disclosed and can be initiated remotely by submitting a crafted remark value via the customer form. Because the application does not perform adequate escaping or filtering of user input, remote attackers can force the execution of malicious scripts in the browser context of any authenticated or unauthenticated user who views the affected page. The impact is limited to the browsers of end users and does not compromise the server itself, but it can lead to credential theft or other client‑side damage.
OpenCVE Enrichment