Impact
The vulnerability is a stack‑based buffer overflow triggered in the Customer Search Module of DefaultFuction’s Customer‑Relationship‑Management‑In‑C‑Project version 2.0. The overflow results from an unbounded call to the C function gets, allowing an attacker to overflow the stack and potentially execute arbitrary code. This weakness is categorized under CWE‑119 and CWE‑121 and offers an attacker a pathway to compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
Affected systems are installations of DefaultFuction’s Customer‑Relationship‑Management‑In‑C‑Project, specifically version 2.0 of the software. The public source repository for this project is hosted on GitHub under the DefaultFuction organization.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, but the absence of an EPSS score means current exploitation potential is unclear. The vulnerability is confirmed publicly, and the project has acknowledged it is being processed. An attacker can trigger the overflow remotely by manipulating the input to the Customer Search Module. The vulnerability is not listed in the CISA KEV catalog, so there is no known exploitation campaign yet, but the remote nature and stack corruption provide a high‑impact vector if exploited.
OpenCVE Enrichment