PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105287 feelec-yishu CVE debrief

A SQL injection vulnerability was found in feelec-yishu feelcrm-os 1.0.0, specifically in the getMemberByGroups endpoint of the AjaxRequestController.class.php file. The vulnerability allows remote attackers to inject SQL code by manipulating the groups[] argument. The project was informed of the problem but has not responded yet. The vulnerability's impact and remediation are not fully established, and defenders should assess exposure and prioritize verification of affected versions. The SQL injection vulnerability requires defenders to assess exposure, prioritize verification of affected versions, and consider compensating controls until remediation is available.

Vendor
feelec-yishu
Product
feelcrm-os
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-05
Advisory published
2026-10-05
Advisory updated
2026-10-05

Who should care

Defenders responsible for feelec-yishu feelcrm-os deployments should assess exposure and prioritize verification of affected versions. They should also consider compensating controls until remediation is available and monitor for potential SQL injection attacks. Additionally, defenders should review vendor guidance and security advisories for additional information and perform vulnerability scanning and penetration testing to identify potential

Why it matters

The SQL injection vulnerability in feelec-yishu feelcrm-os 1.0.0 requires defenders to assess exposure, prioritize verification of affected versions, and consider compensating controls until remediation is available.

  • Verify potential SQL injection attacks
  • Assess exposure to the getMemberByGroups endpoint
  • Consider compensating controls until remediation is available
  • Monitor for potential data breaches

Technical summary

The vulnerability is located in the AjaxRequestController.class.php file of the feelec-yishu feelcrm-os 1.0.0. The getMemberByGroups endpoint is susceptible to SQL injection attacks due to improper handling of the groups[] argument. The vulnerability allows remote attackers to inject SQL code, potentially leading to data breaches or system compromise. Defenders should prioritize verifying the affected versions and assessing exposure, as the vulnerability's impact and remediation are not fully established. The SQL injection vulnerability requires defenders to assess exposure, prioritize verification of affected versions, and consider compensating controls until remediation is available.

Defensive priority

Defenders should prioritize verifying the affected versions and assessing exposure, as the vulnerability's impact and remediation are not fully established.

Recommended defensive actions

  • Verify the affected versions of feelec-yishu feelcrm-os
  • Assess exposure to the getMemberByGroups endpoint
  • Monitor for potential SQL injection attacks
  • Consider compensating controls until remediation is available
  • Review vendor guidance and security advisories for additional information
  • Perform vulnerability scanning and penetration testing to identify potential vulnerabilities
  • Implement additional security controls to prevent exploitation

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but the vendor's response and remediation efforts are unknown. The vulnerability is located in the AjaxRequestController.class.php file of the feelec-yishu feelcrm-os 1.0.0. The getMemberByGroups endpoint is susceptible to SQL injection attacks due to improper handling of the groups[] argument. Defenders should prioritize verifying the affected versions and assessing exposure, as the vulnerability's impact and remediation are not fully established. The project was not

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105287 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105287

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105287 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105287

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.