CVE-2026-86172: DefaultFuction CRM delete.php sql injection
A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be initiated remotely, but the CVSS vector indicates that low-level privileges are required. No user interaction is required.
Which component and input should be prioritized for review?
Review the customer deletion endpoint at /modules/customers/delete.php, specifically handling of the ID argument. The vulnerable function within that file is not identified in the available information.
How urgent is remediation?
A public exploit is available, increasing the likelihood of exploitation. The reported impact includes confidentiality, integrity, and availability effects, each rated low.