在 feeltec-yishu feelcrm-os 1.0.0 中发现了一个漏洞。该漏洞影响的是组件 Crm Endpoint 中文件 App/ThinkPHP/Common/functions.php 的 IndexController::index 函数。对参数 redirect_url 的特定操控可导致跨站脚本攻击(XSS)。攻击者可以从远程发起攻击。该漏洞已被公开披露,并且可利用。项目方已通过问题报告早期知晓此问题,但截至目前尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| feelec-yishu | feelcrm-os | 1.0.0 |
cpe:2.3:a:feelec-yishu:feelcrm-os:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105290 | 7.3 HIGH | feelec-yishu feelcrm-os getCurlData Endpoint GoogleController.class.php server-side reques |
| CVE-2026-105287 | 6.3 MEDIUM | feelec-yishu feelcrm-os getMemberByGroups Endpoint AjaxRequestController.class.php sql inj |
| CVE-2026-105289 | 3.5 LOW | feelec-yishu feelcrm-os Create Customer Endpoint CrmDefineFormModel.class.php htmlspecialc |
No comments yet