Impact
The DefaultFuction CRM 1.0.0 contains a flaw in modules/orders/delete.php that lets an attacker manipulate the ID argument to inject arbitrary SQL statements. This leads to execution of unauthorized queries against the database, potentially enabling data disclosure, tampering, or deletion. The publicly disclosed exploit is operable from remote sources according to the provided description.
Affected Systems
Affected parties are users running DefaultFuction CRM, specifically version 1.0.0. No other product variants or versions are mentioned, so any deployment of this release is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 classifies this flaw as moderate severity, and the absence of an EPSS value means the exploitation probability is unknown in current data. It is not listed in the CISA KEV catalog, but the vulnerability is publicly documented and has known remote exploitation paths. The combination of remote attack possibility, data integrity impact, and moderate severity suggests a tangible risk that warrants prompt attention.
OpenCVE Enrichment