Executive brief
Chanjet CRM is a cloud-based financial and business management platform used by enterprises for accounting and operations. The application contains an unauthenticated SQL injection vulnerability that allows remote attackers to bypass authentication and execute arbitrary database queries. Attackers can exploit this flaw to extract sensitive financial data, user credentials, and other confidential information from the underlying database without any special access.
Technical details
The vulnerability exists in the get_usedspace.php endpoint where the site_id GET parameter is not properly sanitized or parameterized, allowing UNION-based SQL injection attacks. An unauthenticated remote attacker can craft malicious SQL queries through the webservice endpoint to extract arbitrary data from the database. The flaw requires only network access and a crafted HTTP request; no authentication or user interaction is needed.
Affected products
- Chanjet CRM
Timeline
- 2026-09-18: disclosed
- 2023-10-18: other: Exploitation evidence first observed by Shadowserver Foundation