{"id":"CVE-2021-48008","aliases":[],"url":"https://o3.security/vulnerability/CVE-2021-48008","summary":"Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice…","details":"Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice endpoint. Attackers can exploit the lack of input sanitization or parameterization through UNION-based injection techniques to extract sensitive data from the underlying database. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18.","published":"2026-09-18T19:16:40.563","modified":"2026-09-18T19:16:40.563","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://raw.githubusercontent.com/projectdiscovery/nuclei-templates/main/http/vulnerabilities/chanjet-tplus/chanjet-crm-sqli.yaml"},{"type":"WEB","url":"https://www.chanjet.com/"},{"type":"WEB","url":"https://www.cnvd.org.cn/flaw/show/CNVD-2021-12845"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/chanjet-crm-sql-injection-via-get-usedspace-php"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-18T19:16:40.563"}}