Unauthenticated SQL Injection in Chanjet CRM by Chanjet
CVE-2021-48008
8.7HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 18 September 2026
What is CVE-2021-48008?
Chanjet CRM is susceptible to an unauthenticated SQL injection vulnerability. This flaw allows remote attackers to execute arbitrary SQL queries by manipulating the 'site_id' parameter in the webservice endpoint. The vulnerability arises due to inadequate input sanitization and parameterization, enabling attackers to utilize UNION-based injection techniques to extract sensitive information from the database. Evidence of exploitation was first reported by the Shadowserver Foundation on October 18, 2023. It is critical for users to apply security patches released by Chanjet and to assess their exposure to potential data breaches.
Affected Version(s)
CRM *
