Impact
This vulnerability occurs when an attacker manipulates the gblOrgID argument in the jxf_dump_table.php file of Chanjet CRM, allowing unsanitized data to be incorporated directly into SQL statements. The resulting SQL injection flaw can lead to unauthorized data disclosure, data modification, or deletion, depending on the database schema and user privileges. The exploit requires only remote access to the web application and has been publicly documented, indicating that attackers can readily leverage it against exposed systems.
Affected Systems
Chanjet, CRM versions up to and including 20260707 are affected. No later version information is available in this advisory. The flaw resides in unspecified portions of the jxf_dump_table.php processing that accept the gblOrgID parameter.
Risk and Exploitability
The CVSS score for this vulnerability is 6.9, indicating a medium severity. Because the EPSS score is not available, the historical exploitation probability is unclear; however, the public availability of an exploit and the lack of vendor remediation suggest a realistic risk. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, as the flaw can be triggered by any user who can send HTTP requests to the affected script. An attacker could, therefore, compromise a user account with web access and potentially gain broader access to the underlying database if privilege escalation gaps exist.
OpenCVE Enrichment