GHSA-pcc8-7q79-f457LowCVSS 6.3
A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown...
🔗 CVE IDs covered (1)
📋 Description
A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-86171
- https://github.com/DefaultFuction/Customer-Relationship-Management-System/issues/4
- https://vuldb.com/cve/CVE-2026-86171
- https://vuldb.com/submit/895743
- https://vuldb.com/vuln/399309
- https://vuldb.com/vuln/399309/cti
- https://github.com/advisories/GHSA-pcc8-7q79-f457