CVE-2026-105288 | feelec-yishu feelcrm-os 1.0.0 Crm Endpoint functions.php IndexController::index redirect_url cross site scripting
A vulnerability was found in feelec-yishu feelcrm-os 1.0.0. It has been declared as problematic. Affected by this vulnerability is the function IndexController::index of the file App/ThinkPHP/Common/functions.php of the component Crm Endpoint. Such manipulation of the argument redirect_url leads to cross site scripting.
This vulnerability is listed as CVE-2026-105288. The attack may be performed from remote. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More