在 feelec-yishu feelcrm-os 1.0.0 中发现了一个漏洞。该漏洞影响了组件“部门搜索端点”中文件 App/Feelcrm/Index/Controller/GroupController.class.php 的 GroupController::index 函数。对参数 keyword 的操作可导致跨站脚本攻击(XSS)。攻击可以从远程发起,且利用代码已公开,可能被滥用。项目方已通过问题报告在早期获知此问题,但尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| feelec-yishu | feelcrm-os | 1.0.0 |
cpe:2.3:a:feelec-yishu:feelcrm-os:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105290 | 7.3 HIGH | feelec-yishu feelcrm-os getCurlData Endpoint GoogleController.class.php server-side reques |
| CVE-2026-105287 | 6.3 MEDIUM | feelec-yishu feelcrm-os getMemberByGroups Endpoint AjaxRequestController.class.php sql inj |
| CVE-2026-105288 | 4.3 MEDIUM | feelec-yishu feelcrm-os Crm Endpoint functions.php index cross site scripting |
| CVE-2026-105289 | 3.5 LOW | feelec-yishu feelcrm-os Create Customer Endpoint CrmDefineFormModel.class.php htmlspecialc |
No comments yet