Description
A vulnerability was found in feelec-yishu feelcrm-os 1.0.0. Affected by this issue is the function htmlspecialchars_decode of the file App/Feelcrm/Common/Model/CrmDefineFormModel.class.php of the component Create Customer Endpoint. Performing a manipulation of the argument customer_form[remark] results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-10-05
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting affecting client browsers
Action: Apply Patch
AI Analysis

Impact

A cross‑site scripting flaw exists in the create‑customer endpoint of the feelcrm-os application. The vulnerability occurs when user supplied data in the customer_form[remark] field is processed by the library function htmlspecialchars_decode before being rendered on a webpage. Because the input is not properly sanitized or encoded, an attacker can inject arbitrary HTML or JavaScript that will be executed in the context of other users who view the remark. The flaw provides a path for information disclosure, defacement, or cookie theft and is classified as an input validation weakness (CWE‑79) and a context‑dependent code execution issue (CWE‑94).

Affected Systems

The affected product is feelcrm‑os, version 1.0.0, developed by feelec‑yishu. The vulnerability resides in the file CrmDefineFormModel.class.php within the App/Feelcrm/Common/Model directory of this release. CPE entry cpe:2.3:a:feelec‑yishu:feelcrm‑os:*:*:*:*:*:*:*:* captures the affected platform.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. EPSS for this vulnerability is not available, so the current exploitation probability cannot be quantified. The flaw is currently not listed in the CISA KEV catalog. The exploit is publicly disclosed and can be initiated remotely by submitting a crafted remark value via the customer form. Because the application does not perform adequate escaping or filtering of user input, remote attackers can force the execution of malicious scripts in the browser context of any authenticated or unauthenticated user who views the affected page. The impact is limited to the browsers of end users and does not compromise the server itself, but it can lead to credential theft or other client‑side damage.

Generated by OpenCVE AI on October 5, 2026 at 11:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s official patch to feelcrm‑os once it becomes available.
  • If a patch is not yet released, replace the call to htmlspecialchars_decode in CrmDefineFormModel.class.php with safe rendering logic, encoding the remark content with a proper escaping function before output to the client.
  • Implement a Content Security Policy that disallows inline scripts and limits script sources to trusted domains, thereby reducing the effectiveness of any injected code.

Generated by OpenCVE AI on October 5, 2026 at 11:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in feelec-yishu feelcrm-os 1.0.0. Affected by this issue is the function htmlspecialchars_decode of the file App/Feelcrm/Common/Model/CrmDefineFormModel.class.php of the component Create Customer Endpoint. Performing a manipulation of the argument customer_form[remark] results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Title feelec-yishu feelcrm-os Create Customer Endpoint CrmDefineFormModel.class.php htmlspecialchars_decode cross site scripting
First Time appeared Feelec-yishu
Feelec-yishu feelcrm-os
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:feelec-yishu:feelcrm-os:*:*:*:*:*:*:*:*
Vendors & Products Feelec-yishu
Feelec-yishu feelcrm-os
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Feelec-yishu Feelcrm-os
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T12:45:46.293Z

Reserved: 2026-10-04T22:44:23.426Z

Link: CVE-2026-105289

cve-icon Vulnrichment

Updated: 2026-10-05T12:45:40.406Z

cve-icon NVD

Status : Received

Published: 2026-10-05T11:16:46.617

Modified: 2026-10-05T13:16:52.650

Link: CVE-2026-105289

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T12:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')