Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 05 Oct 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in feelec-yishu feelcrm-os 1.0.0. This issue affects some unknown processing of the file App/Feelcrm/Crm/Controller/UploadController.class.php of the component UploadTicketFile Endpoint. Such manipulation of the argument cmd leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | feelec-yishu feelcrm-os UploadTicketFile Endpoint UploadController.class.php unrestricted upload | |
| First Time appeared |
Feelec-yishu
Feelec-yishu feelcrm-os |
|
| Weaknesses | CWE-284 CWE-434 |
|
| CPEs | cpe:2.3:a:feelec-yishu:feelcrm-os:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Feelec-yishu
Feelec-yishu feelcrm-os |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-05T19:30:12.153Z
Reserved: 2026-10-05T10:31:22.731Z
Link: CVE-2026-105389
No data.
Status : Received
Published: 2026-10-05T20:17:10.610
Modified: 2026-10-05T20:17:10.610
Link: CVE-2026-105389
No data.
OpenCVE Enrichment
Updated: 2026-10-05T22:15:15Z