---
cve: "CVE-2026-105287"
severity: "MEDIUM"
cvss: 5.3
epss: "0.3%"
vendor: "feelec-yishu"
kev: false
exploited: false
published: "2026-10-05 09:45:12"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-10-10T12:10:10+02:00"
---

# CVE-2026-105287

> 5.3 MEDIUM · 🧪 PoC

## Beschreibung

A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpoint. This manipulation of the argument groups[] causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

## CNA-Record (Kanon, cvelistV5)

- CNA: **VulDB**
- State: PUBLISHED
- Stand: 2026-10-05 11:56:26
- CNA-CVSS: **5.3** (`CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **poc**
  - Automatable: **no**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |

## Schwachstellen-Klasse

- **CWE-74** — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
  The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
- **CWE-89** — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
  The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as…

## Angriffsmuster (CAPEC)

- [CAPEC-10 — Buffer Overflow via Environment Variables](https://capec.mitre.org/data/definitions/10.html) _(Severity: High)_
- [CAPEC-13 — Subverting Environment Variable Values](https://capec.mitre.org/data/definitions/13.html) _(Severity: Very High)_
- [CAPEC-14 — Client-side Injection-induced Buffer Overflow](https://capec.mitre.org/data/definitions/14.html) _(Severity: High)_
- [CAPEC-101 — Server Side Include (SSI) Injection](https://capec.mitre.org/data/definitions/101.html) _(Severity: High)_
- [CAPEC-105 — HTTP Request Splitting](https://capec.mitre.org/data/definitions/105.html) _(Severity: High)_
- [CAPEC-108 — Command Line Execution through SQL Injection](https://capec.mitre.org/data/definitions/108.html) _(Severity: Very High)_
- [CAPEC-120 — Double Encoding](https://capec.mitre.org/data/definitions/120.html) _(Severity: Medium)_
- [CAPEC-135 — Format String Injection](https://capec.mitre.org/data/definitions/135.html) _(Severity: High)_

## ATT&CK-Techniken

- [T1562.003 — Impair Defenses:Impair Command History Logging](https://attack.mitre.org/techniques/T1562/003/)
- [T1574.006 — Hijack Execution Flow:Dynamic Linker Hijacking](https://attack.mitre.org/techniques/T1574/006/)
- [T1574.007 — Hijack Execution Flow:Path Interception by PATH Environment ](https://attack.mitre.org/techniques/T1574/007/)

## Referenzen

- <https://vuldb.com/vuln/413468>
- <https://vuldb.com/vuln/413468/cti>
- <https://vuldb.com/cve/CVE-2026-105287>
- <https://vuldb.com/submit/977517>
- <https://github.com/feelec-yishu/feelcrm-os/issues/1>
- <https://github.com/feelec-yishu/feelcrm-os/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/sicherheitsluecken/cve-2026-105287/) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
