Junglewise Threat Intelligence

CVE-2021-48008: Chanjet CRM unauthenticated SQL injection in get_usedspace

CVE-2021-48008 · Severity: high · CVSS 7.5 · Published 2026-09-18

Executive brief

Chanjet CRM is a cloud-based financial and business management platform used by enterprises for accounting and operations. The application contains an unauthenticated SQL injection vulnerability that allows remote attackers to bypass authentication and execute arbitrary database queries. Attackers can exploit this flaw to extract sensitive financial data, user credentials, and other confidential information from the underlying database without any special access.

Technical details

The vulnerability exists in the get_usedspace.php endpoint where the site_id GET parameter is not properly sanitized or parameterized, allowing UNION-based SQL injection attacks. An unauthenticated remote attacker can craft malicious SQL queries through the webservice endpoint to extract arbitrary data from the database. The flaw requires only network access and a crafted HTTP request; no authentication or user interaction is needed.

Affected products

  • Chanjet CRM

Timeline

  • 2026-09-18: disclosed
  • 2023-10-18: other: Exploitation evidence first observed by Shadowserver Foundation

References

Related threats