PatchSiren

feelec-yishu CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW feelec-yishu CVE published 2026-10-05

CVE-2026-105291

A vulnerability was identified in feelec-yishu feelcrm-os 1.0.0, affecting the Department Search Endpoint. The manipulation of the argument keyword leads to cross-site scripting. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet. The vulnerability allows remote cross-site scripting attacks, and defenders should verify the [truncated]

MEDIUM feelec-yishu CVE published 2026-10-05

CVE-2026-105290

A vulnerability was determined in feelec-yishu feelcrm-os 1.0.0. This affects an unknown part of the file App/Feelcrm/Index/Controller/GoogleController.class.php of the component getCurlData Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project wa [truncated]

LOW feelec-yishu CVE published 2026-10-05

CVE-2026-105289

A vulnerability was found in feelec-yishu feelcrm-os 1.0.0. Affected by this issue is the function htmlspecialchars_decode of the file App/Feelcrm/Common/Model/CrmDefineFormModel.class.php of the component Create Customer Endpoint. Performing a manipulation of the argument customer_form[remark] results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made publi [truncated]

LOW feelec-yishu CVE published 2026-10-05

CVE-2026-105288

A vulnerability was found in the feelec-yishu feelcrm-os 1.0.0, affecting the IndexController::index function in App/ThinkPHP/Common/functions.php. This vulnerability allows for cross-site scripting (XSS) due to improper handling of the redirect_url argument. The attack can be performed remotely, and the exploit has been publicly disclosed. However, the project has not responded to the issue report yet.

LOW feelec-yishu CVE published 2026-10-05

CVE-2026-105287

A SQL injection vulnerability was found in feelec-yishu feelcrm-os 1.0.0, specifically in the getMemberByGroups endpoint of the AjaxRequestController.class.php file. The vulnerability allows remote attackers to inject SQL code by manipulating the groups[] argument. The project was informed of the problem but has not responded yet. The vulnerability's impact and remediation are not fully established, and d [truncated]