{"id":"CVE-2021-48008","published":"2026-09-18T19:16:40.563","lastModified":"2026-09-24T21:08:55.030","description":"Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice endpoint. Attackers can exploit the lack of input sanitization or parameterization through UNION-based injection techniques to extract sensitive data from the underlying database. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://raw.githubusercontent.com/projectdiscovery/nuclei-templates/main/http/vulnerabilities/chanjet-tplus/chanjet-crm-sqli.yaml","tags":[]},{"url":"https://www.chanjet.com/","tags":[]},{"url":"https://www.cnvd.org.cn/flaw/show/CNVD-2021-12845","tags":[]},{"url":"https://www.vulncheck.com/advisories/chanjet-crm-sql-injection-via-get-usedspace-php","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}