Metrics
Affected Vendors & Products
Tue, 09 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chanjet
Chanjet chanjet Crm |
|
| Vendors & Products |
Chanjet
Chanjet chanjet Crm |
Mon, 08 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 07 Dec 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in Chanjet CRM up to 20251121. Affected is an unknown function of the file /tools/jxf_dump_table_demo.php. The manipulation of the argument gblOrgID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Chanjet CRM jxf_dump_table_demo.php sql injection | |
| Weaknesses | CWE-74 CWE-89 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-12-07T11:32:05.273Z
Updated: 2025-12-08T19:42:27.517Z
Reserved: 2025-12-06T14:17:48.442Z
Link: CVE-2025-14189
Updated: 2025-12-08T19:42:24.301Z
Status : Awaiting Analysis
Published: 2025-12-07T12:15:47.610
Modified: 2025-12-08T18:26:49.133
Link: CVE-2025-14189
No data.