GHSA-x5gc-r7qf-2h87HighCVSS 7.5
Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers...
🔗 CVE IDs covered (1)
📋 Description
Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice endpoint. Attackers can exploit the lack of input sanitization or parameterization through UNION-based injection techniques to extract sensitive data from the underlying database. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2021-48008
- https://raw.githubusercontent.com/projectdiscovery/nuclei-templates/main/http/vulnerabilities/chanjet-tplus/chanjet-crm-sqli.yaml
- https://www.chanjet.com
- https://www.cnvd.org.cn/flaw/show/CNVD-2021-12845
- https://www.vulncheck.com/advisories/chanjet-crm-sql-injection-via-get-usedspace-php
- https://github.com/advisories/GHSA-x5gc-r7qf-2h87