VYPR

feelcrm-os

by Feelec Yishu

CVEs (5)

  • CVE-2026-105290HigOct 5, 2026
    risk 0.47cvss 7.3epss —

    A vulnerability was determined in feelec-yishu feelcrm-os 1.0.0. This affects an unknown part of the file App/Feelcrm/Index/Controller/GoogleController.class.php of the component getCurlData Endpoint. Executing a manipulation of the argument url can lead to server-side request…

  • CVE-2026-105287MedOct 5, 2026
    risk 0.41cvss 6.3epss —

    A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpoint. This manipulation of the argument groups[] causes sql injection. The attack…

  • CVE-2026-105291MedOct 5, 2026
    risk 0.28cvss 4.3epss —

    A vulnerability was identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function GroupController::index of the file App/Feelcrm/Index/Controller/GroupController.class.php of the component Department Search Endpoint. The manipulation of the argument…

  • CVE-2026-105288MedOct 5, 2026
    risk 0.28cvss 4.3epss —

    A vulnerability has been found in feelec-yishu feelcrm-os 1.0.0. Affected by this vulnerability is the function IndexController::index of the file App/ThinkPHP/Common/functions.php of the component Crm Endpoint. Such manipulation of the argument redirect_url leads to cross site…

  • CVE-2026-105289LowOct 5, 2026
    risk 0.23cvss 3.5epss —

    A vulnerability was found in feelec-yishu feelcrm-os 1.0.0. Affected by this issue is the function htmlspecialchars_decode of the file App/Feelcrm/Common/Model/CrmDefineFormModel.class.php of the component Create Customer Endpoint. Performing a manipulation of the argument…