A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the...
zetlyn/cve-ghsa vulnerability ghsa GHSA-235g-9xc7-pvrh cve CVE-2026-105287 known 2026-10-05
https://github.com/advisories/GHSA-235g-9xc7-pvrh
Properties
| cvss | 6.3receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-105287",
"cvss": {
"score": 6.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 6.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 2.1,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-74",
"name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
}
],
"description": "A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpoint. This manipulation of the argument groups[] causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.",
"ghsa_id": "GHSA-235g-9xc7-pvrh",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-235g-9xc7-pvrh",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-235g-9xc7-pvrh"
},
{
"type": "CVE",
"value": "CVE-2026-105287"
}
],
"nvd_published_at": "2026-10-05T10:16:41Z",
"published_at": "2026-10-05T12:31:25Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-105287",
"https://github.com/feelec-yishu/feelcrm-os/issues/1",
"https://github.com/feelec-yishu/feelcrm-os",
"https://vuldb.com/cve/CVE-2026-105287",
"https://vuldb.com/submit/977517",
"https://vuldb.com/vuln/413468",
"https://vuldb.com/vuln/413468/cti",
"https://github.com/advisories/GHSA-235g-9xc7-pvrh"
],
"repository_advisory_url": null,
"severity": "low",
"source_code_location": "",
"summary": "A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the...",
"type": "unreviewed",
"updated_at": "2026-10-05T12:31:34Z",
"url": "https://api.github.com/advisories/GHSA-235g-9xc7-pvrh",
"vulnerabilities": [],
"withdrawn_at": null
} |
|---|---|
| cwe | CWE-74receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-105287",
"cvss": {
"score": 6.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 6.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 2.1,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-74",
"name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
}
],
"description": "A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpoint. This manipulation of the argument groups[] causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.",
"ghsa_id": "GHSA-235g-9xc7-pvrh",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-235g-9xc7-pvrh",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-235g-9xc7-pvrh"
},
{
"type": "CVE",
"value": "CVE-2026-105287"
}
],
"nvd_published_at": "2026-10-05T10:16:41Z",
"published_at": "2026-10-05T12:31:25Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-105287",
"https://github.com/feelec-yishu/feelcrm-os/issues/1",
"https://github.com/feelec-yishu/feelcrm-os",
"https://vuldb.com/cve/CVE-2026-105287",
"https://vuldb.com/submit/977517",
"https://vuldb.com/vuln/413468",
"https://vuldb.com/vuln/413468/cti",
"https://github.com/advisories/GHSA-235g-9xc7-pvrh"
],
"repository_advisory_url": null,
"severity": "low",
"source_code_location": "",
"summary": "A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the...",
"type": "unreviewed",
"updated_at": "2026-10-05T12:31:34Z",
"url": "https://api.github.com/advisories/GHSA-235g-9xc7-pvrh",
"vulnerabilities": [],
"withdrawn_at": null
} |
| severity | low Below 4.0. receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-105287",
"cvss": {
"score": 6.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 6.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 2.1,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-74",
"name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
}
],
"description": "A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpoint. This manipulation of the argument groups[] causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.",
"ghsa_id": "GHSA-235g-9xc7-pvrh",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-235g-9xc7-pvrh",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-235g-9xc7-pvrh"
},
{
"type": "CVE",
"value": "CVE-2026-105287"
}
],
"nvd_published_at": "2026-10-05T10:16:41Z",
"published_at": "2026-10-05T12:31:25Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-105287",
"https://github.com/feelec-yishu/feelcrm-os/issues/1",
"https://github.com/feelec-yishu/feelcrm-os",
"https://vuldb.com/cve/CVE-2026-105287",
"https://vuldb.com/submit/977517",
"https://vuldb.com/vuln/413468",
"https://vuldb.com/vuln/413468/cti",
"https://github.com/advisories/GHSA-235g-9xc7-pvrh"
],
"repository_advisory_url": null,
"severity": "low",
"source_code_location": "",
"summary": "A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the...",
"type": "unreviewed",
"updated_at": "2026-10-05T12:31:34Z",
"url": "https://api.github.com/advisories/GHSA-235g-9xc7-pvrh",
"vulnerabilities": [],
"withdrawn_at": null
} |
Text
A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the...
A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpoint. This manipulation of the argument groups[] causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.