Impact
A weakness was identified in DefaultFuction CRM 1.0.0 where an unknown function in /modules/orders/edit.php can be manipulated by altering the ID argument. This misuse allows an attacker to inject arbitrary SQL statements, potentially gaining unauthorized access to or modification of sensitive data in the database. The vulnerability is a classic SQL injection flaw and is listed as CWE-89 in the CVE record.
Affected Systems
The affected product is DefaultFuction CRM version 1.0.0. No other vendor or product versions are explicitly mentioned in the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is currently unavailable, and the issue is not listed in the CISA KEV catalog. The attack vector is remote, as the flaw can be triggered over the network by sending a crafted request to the edit.php endpoint. Publicly available exploits have been disclosed, which increases concern for organizations still running the vulnerable version.
OpenCVE Enrichment