Impact
The GroupController::index function in the Department Search endpoint of feelec-yishu feelcrm-os fails to sanitize the keyword argument, enabling attackers to inject arbitrary script that the browser will execute when rendering the page. This cross‑site scripting flaw, associated with CWE‑79, allows remote exploitation via a crafted URL or form input, potentially leading to session hijacking, defacement, or data theft. The CVSS score of 5.3 reflects a moderate impact on confidentiality, integrity and availability, while the presence of a publicly available exploit signals that the vulnerability is likely to be abused.
Affected Systems
Affected systems are feelec-yishu feelcrm-os version 1.0.0. The vulnerability exists in the GroupController::index method located in App/Feelcrm/Index/Controller/GroupController.class.php. The Department Search endpoint renders the keyword parameter without proper encoding or escaping, making any user who views the page susceptible to the XSS payload.
Risk and Exploitability
The risk assessment indicates a CVSS score of 5.3 and an EPSS score that is currently not publicly available. The vulnerability is not listed in CISA's KEV catalog, but the existence of a publicly provided exploit demonstrates that it can be leveraged remotely. Attackers only need to supply a malicious keyword value in a URL or form; no authentication or privileged access is required, making this a low barrier to exploitation.
OpenCVE Enrichment