CVE-2026-86171: DefaultFuction CRM delete.php sql injection
Published Sep 6, 2026
·Updated
A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Affected Software
1 affected component
DefaultFuction CRM=1.0.0
Event History
Sep 6, 2026
CVE Published
via MITRE·06:15 AM
Data Sourced
via MITRE·06:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The vector indicates that exploitation is remote and requires low privileges. No user interaction is required.
2
Which endpoint and parameter should defenders prioritize for review?
Review /modules/orders/delete.php, specifically handling of the ID argument. The reported issue is SQL injection caused by manipulation of that parameter.
3
How likely is exploitation in the near term?
A public exploit has been disclosed and may be used. The exploit maturity is rated proof-of-concept.