SQL Injection Vulnerability in Chanjet CRM Software
CVE-2025-5152
Key Information:
Badges
What is CVE-2025-5152?
A SQL injection vulnerability exists in Chanjet CRM, affecting versions up to 20250510. The issue is found in the 'newActivityedit.php' file, where improper handling of the 'gblOrgID' parameter allows remote attackers to manipulate SQL queries. This can lead to unauthorized access to sensitive information within the application. As the vulnerability has been publicly disclosed and the vendor has not responded to notifications, users are strongly advised to review their security measures and apply necessary safeguards to their installations.
Affected Version(s)
CRM 20250510
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
