SQL Injection Vulnerability in DefaultFuction CRM
CVE-2026-86171
Key Information:
- Vendor
Defaultfuction
- Status
- Vendor
- CVE Published:
- 6 September 2026
Badges
What is CVE-2026-86171?
A security vulnerability has been identified within DefaultFuction CRM 1.0.0, specifically affecting the /modules/orders/delete.php file. This vulnerability allows an attacker to manipulate the ID argument, leading to SQL injection attacks from remote locations. The exploit has been publicly disclosed, making systems using this version vulnerable to unauthorized access and potential data compromise. It is crucial for users to review their security measures and apply necessary patches or updates to mitigate this risk.
Affected Version(s)
CRM 1.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
