Description
A vulnerability was identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function GroupController::index of the file App/Feelcrm/Index/Controller/GroupController.class.php of the component Department Search Endpoint. The manipulation of the argument keyword leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-10-05
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The GroupController::index function in the Department Search endpoint of feelec-yishu feelcrm-os fails to sanitize the keyword argument, enabling attackers to inject arbitrary script that the browser will execute when rendering the page. This cross‑site scripting flaw, associated with CWE‑79, allows remote exploitation via a crafted URL or form input, potentially leading to session hijacking, defacement, or data theft. The CVSS score of 5.3 reflects a moderate impact on confidentiality, integrity and availability, while the presence of a publicly available exploit signals that the vulnerability is likely to be abused.

Affected Systems

Affected systems are feelec-yishu feelcrm-os version 1.0.0. The vulnerability exists in the GroupController::index method located in App/Feelcrm/Index/Controller/GroupController.class.php. The Department Search endpoint renders the keyword parameter without proper encoding or escaping, making any user who views the page susceptible to the XSS payload.

Risk and Exploitability

The risk assessment indicates a CVSS score of 5.3 and an EPSS score that is currently not publicly available. The vulnerability is not listed in CISA's KEV catalog, but the existence of a publicly provided exploit demonstrates that it can be leveraged remotely. Attackers only need to supply a malicious keyword value in a URL or form; no authentication or privileged access is required, making this a low barrier to exploitation.

Generated by OpenCVE AI on October 5, 2026 at 12:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a fixed version of feelcrm‑os when one is released
  • Apply any available vendor patch as soon as it becomes available
  • Modify GroupController::index to perform proper input validation and output encoding on the keyword parameter to neutralize XSS payloads

Generated by OpenCVE AI on October 5, 2026 at 12:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function GroupController::index of the file App/Feelcrm/Index/Controller/GroupController.class.php of the component Department Search Endpoint. The manipulation of the argument keyword leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Title feelec-yishu feelcrm-os Department Search Endpoint GroupController.class.php index cross site scripting
First Time appeared Feelec-yishu
Feelec-yishu feelcrm-os
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:feelec-yishu:feelcrm-os:*:*:*:*:*:*:*:*
Vendors & Products Feelec-yishu
Feelec-yishu feelcrm-os
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Feelec-yishu Feelcrm-os
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T11:00:21.446Z

Reserved: 2026-10-04T22:44:30.135Z

Link: CVE-2026-105291

cve-icon Vulnrichment

Updated: 2026-10-05T11:00:17.287Z

cve-icon NVD

Status : Received

Published: 2026-10-05T11:16:46.983

Modified: 2026-10-05T11:16:46.983

Link: CVE-2026-105291

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T13:00:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')