CVE-2026-105289 | feelec-yishu feelcrm-os 1.0.0 Create Customer Endpoint CrmDefineFormModel.class.php htmlspecialchars_decode customer_form[remark] cross site scripting
A vulnerability was found in feelec-yishu feelcrm-os 1.0.0. It has been rated as problematic. Affected by this issue is the function htmlspecialchars_decode of the file App/Feelcrm/Common/Model/CrmDefineFormModel.class.php of the component Create Customer Endpoint. Performing a manipulation of the argument customer_form[remark] results in cross site scripting.
This vulnerability is cataloged as CVE-2026-105289. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More