CVE-2026-105291 | feelec-yishu feelcrm-os 1.0.0 Department Search Endpoint GroupController.class.php GroupController::index keyword cross site scripting
A vulnerability identified as problematic has been detected in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function GroupController::index of the file App/Feelcrm/Index/Controller/GroupController.class.php of the component Department Search Endpoint. The manipulation of the argument keyword leads to cross site scripting.
This vulnerability is documented as CVE-2026-105291. The attack can be initiated remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More