CVE-2026-105388 | feelec-yishu feelcrm-os 1.0.0 Member Endpoint MemberController.class.php index group_id sql injection
A vulnerability was found in feelec-yishu feelcrm-os 1.0.0. It has been rated as critical. This vulnerability affects the function index of the file App/Feelcrm/Index/Controller/MemberController.class.php of the component Member Endpoint. This manipulation of the argument group_id causes sql injection.
This vulnerability is handled as CVE-2026-105388. The attack can be initiated remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More