VYPR

Chanjet CMS

by Chanjet

CVEs (3)

  • CVE-2021-48008HigSep 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice endpoint. Attackers can exploit the lack of input sanitization or parameterization…

  • CVE-2026-84111HigSep 1, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in Chanjet CRM up to 20260707. This issue affects some unknown processing of the file jxf_dump_table.php. This manipulation of the argument gblOrgID causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may…

  • CVE-2025-5152MedMay 25, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability classified as critical was found in Chanjet CRM up to 20250510. This vulnerability affects unknown code of the file /activity/newActivityedit.php?DontCheckLogin=1&id=null&ret=mod1. The manipulation of the argument gblOrgID leads to sql injection. The attack can…