Impact
feelec‑yishu feelcrm‑os 1.0.0 contains a server‑side request forgery vulnerability in the getCurlData endpoint of GoogleController.class.php. The flaw arises from insufficient validation of the URL parameter supplied to the endpoint, allowing an attacker to craft arbitrary HTTP requests from the server. If exploited, the attacker can cause the application to retrieve or post data to internal or external resources, potentially exfiltrating sensitive information, manipulating internal services, or facilitating further attacks. The weakness is identified as CWE‑918, which highlights the lack of proper request validation and domain filtering.
Affected Systems
The affected product is feelec‑yishu feelcrm‑os version 1.0.0. No other affected versions are documented, and the vulnerability has only been observed for this release.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity. It is possible to launch the attack remotely, but the CVE payload does not specify whether authentication is required, so the authentication requirement is uncertain. The publicly disclosed exploit and the lack of vendor response suggest a realistic exploitation risk. The vulnerability is not currently listed in CISA KEV, but its presence in publicly accessible code repositories means attackers could readily discover it. The likely attack vector involves sending a crafted request to the vulnerable endpoint, with the URL parameter pointing to internal or external addresses to which the application will unknowingly connect.
OpenCVE Enrichment