CVE-2026-105388: feelec-yishu feelcrm-os Member Endpoint MemberController.class.php index sql injection
A weakness has been identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function index of the file App/Feelcrm/Index/Controller/MemberController.class.php of the component Member Endpoint. This manipulation of the argument groupid causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be initiated remotely, but the severity vector indicates that the attacker requires low-level privileges. No user interaction is required.
Which deployments are affected?
The issue is reported in feelec-yishu feelcrm-os version 1.0.0, specifically in the Member Endpoint's index function in App/Feelcrm/Index/Controller/MemberController.class.php. It is triggered through manipulation of the group_id argument.
Is public exploit code available?
Yes. The vulnerability report states that an exploit has been made public and could be used in attacks.
Is a vendor fix available?
The provided information does not identify a fix. It states that the project was notified through an issue report but had not responded at the time of reporting.