HIGH 8.7 NVD
CVE-2021-48008
Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GE
Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice endpoint. Attackers can exploit the lack of input sanitization or parameterization through UNION-based injection techniques to extract sensitive data from the underlying database. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18.
References
- https://raw.githubusercontent.com/projectdiscovery/nuclei-templates/main/http/vulnerabilit
- https://www.chanjet.com/
- https://www.cnvd.org.cn/flaw/show/CNVD-2021-12845
- https://www.vulncheck.com/advisories/chanjet-crm-sql-injection-via-get-usedspace-php
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-18 via NVD.
vulnfeed aggregates 14357 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.