Description
A vulnerability was determined in feelec-yishu feelcrm-os 1.0.0. This affects an unknown part of the file App/Feelcrm/Index/Controller/GoogleController.class.php of the component getCurlData Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-10-05
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Server-side Request Forgery
Action: Apply Mitigation
AI Analysis

Impact

feelec‑yishu feelcrm‑os 1.0.0 contains a server‑side request forgery vulnerability in the getCurlData endpoint of GoogleController.class.php. The flaw arises from insufficient validation of the URL parameter supplied to the endpoint, allowing an attacker to craft arbitrary HTTP requests from the server. If exploited, the attacker can cause the application to retrieve or post data to internal or external resources, potentially exfiltrating sensitive information, manipulating internal services, or facilitating further attacks. The weakness is identified as CWE‑918, which highlights the lack of proper request validation and domain filtering.

Affected Systems

The affected product is feelec‑yishu feelcrm‑os version 1.0.0. No other affected versions are documented, and the vulnerability has only been observed for this release.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity. It is possible to launch the attack remotely, but the CVE payload does not specify whether authentication is required, so the authentication requirement is uncertain. The publicly disclosed exploit and the lack of vendor response suggest a realistic exploitation risk. The vulnerability is not currently listed in CISA KEV, but its presence in publicly accessible code repositories means attackers could readily discover it. The likely attack vector involves sending a crafted request to the vulnerable endpoint, with the URL parameter pointing to internal or external addresses to which the application will unknowingly connect.

Generated by OpenCVE AI on October 5, 2026 at 12:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Configure firewall or network controls to limit outbound traffic from the server to only necessary IP addresses or domain ranges.
  • Enforce a whitelist of acceptable URLs for the getCurlData endpoint, rejecting any requests that resolve to disallowed domains.
  • Monitor and log outgoing HTTP requests from the application, inspecting for anomalous destinations, and investigate any suspicious activity.
  • If a vendor patch becomes available, deploy it promptly.

Generated by OpenCVE AI on October 5, 2026 at 12:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in feelec-yishu feelcrm-os 1.0.0. This affects an unknown part of the file App/Feelcrm/Index/Controller/GoogleController.class.php of the component getCurlData Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Title feelec-yishu feelcrm-os getCurlData Endpoint GoogleController.class.php server-side request forgery
First Time appeared Feelec-yishu
Feelec-yishu feelcrm-os
Weaknesses CWE-918
CPEs cpe:2.3:a:feelec-yishu:feelcrm-os:*:*:*:*:*:*:*:*
Vendors & Products Feelec-yishu
Feelec-yishu feelcrm-os
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Feelec-yishu Feelcrm-os
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T10:30:15.436Z

Reserved: 2026-10-04T22:44:26.873Z

Link: CVE-2026-105290

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T11:16:46.807

Modified: 2026-10-05T11:16:46.807

Link: CVE-2026-105290

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T13:00:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)