PatchSiren cyber security CVE debrief
CVE-2026-105287 feelec-yishu CVE debrief
A SQL injection vulnerability was found in feelec-yishu feelcrm-os 1.0.0, specifically in the getMemberByGroups endpoint of the AjaxRequestController.class.php file. The vulnerability allows remote attackers to inject SQL code by manipulating the groups[] argument. The project was informed of the problem but has not responded yet. The vulnerability's impact and remediation are not fully established, and defenders should assess exposure and prioritize verification of affected versions. The SQL injection vulnerability requires defenders to assess exposure, prioritize verification of affected versions, and consider compensating controls until remediation is available.
- Vendor
- feelec-yishu
- Product
- feelcrm-os
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-05
Who should care
Defenders responsible for feelec-yishu feelcrm-os deployments should assess exposure and prioritize verification of affected versions. They should also consider compensating controls until remediation is available and monitor for potential SQL injection attacks. Additionally, defenders should review vendor guidance and security advisories for additional information and perform vulnerability scanning and penetration testing to identify potential
Why it matters
The SQL injection vulnerability in feelec-yishu feelcrm-os 1.0.0 requires defenders to assess exposure, prioritize verification of affected versions, and consider compensating controls until remediation is available.
- Verify potential SQL injection attacks
- Assess exposure to the getMemberByGroups endpoint
- Consider compensating controls until remediation is available
- Monitor for potential data breaches
Technical summary
The vulnerability is located in the AjaxRequestController.class.php file of the feelec-yishu feelcrm-os 1.0.0. The getMemberByGroups endpoint is susceptible to SQL injection attacks due to improper handling of the groups[] argument. The vulnerability allows remote attackers to inject SQL code, potentially leading to data breaches or system compromise. Defenders should prioritize verifying the affected versions and assessing exposure, as the vulnerability's impact and remediation are not fully established. The SQL injection vulnerability requires defenders to assess exposure, prioritize verification of affected versions, and consider compensating controls until remediation is available.
Defensive priority
Defenders should prioritize verifying the affected versions and assessing exposure, as the vulnerability's impact and remediation are not fully established.
Recommended defensive actions
- Verify the affected versions of feelec-yishu feelcrm-os
- Assess exposure to the getMemberByGroups endpoint
- Monitor for potential SQL injection attacks
- Consider compensating controls until remediation is available
- Review vendor guidance and security advisories for additional information
- Perform vulnerability scanning and penetration testing to identify potential vulnerabilities
- Implement additional security controls to prevent exploitation
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but the vendor's response and remediation efforts are unknown. The vulnerability is located in the AjaxRequestController.class.php file of the feelec-yishu feelcrm-os 1.0.0. The getMemberByGroups endpoint is susceptible to SQL injection attacks due to improper handling of the groups[] argument. Defenders should prioritize verifying the affected versions and assessing exposure, as the vulnerability's impact and remediation are not fully established. The project was not
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105287 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105287
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105287 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105287
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/feelec-yishu/feelcrm-os/
-
Source reference
Unverified legacy reference
URL: https://github.com/feelec-yishu/feelcrm-os/issues/1
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-105287
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/977517
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413468
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413468/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.