CVE-2025-6132: Chanjet CRM departmentsetting.php sql injection
Published Jun 16, 2025
·Updated
A vulnerability has been found in Chanjet CRM 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /sysconfig/departmentsetting.php. The manipulation of the argument gblOrgID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Chanjet CRM
Chanjet Chanjet CRM=1.0
Event History
Jun 16, 2025
CVE Published
via MITRE·05:31 PM
Data Sourced
via MITRE·05:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-6132?
CVE-2025-6132 is classified as a critical vulnerability.
2
What software is affected by CVE-2025-6132?
CVE-2025-6132 affects Chanjet CRM version 1.0.
3
How does the CVE-2025-6132 vulnerability occur?
CVE-2025-6132 occurs due to SQL injection vulnerability in the /sysconfig/departmentsetting.php file.
4
Can CVE-2025-6132 be exploited remotely?
Yes, CVE-2025-6132 can be exploited remotely.
5
How can I fix CVE-2025-6132?
To fix CVE-2025-6132, ensure to sanitize user inputs and apply appropriate security updates provided by the vendor.