Junglewise Threat Intelligence

CVE-2025-13788: Chanjet CRM SQL injection in upgradeattribute

CVE-2025-13788 · Severity: high · CVSS 7.3 · Published 2025-11-30

Executive brief

Chanjet CRM, a customer relationship management system, contains a SQL injection vulnerability in its upgrade attribute handler. An attacker can exploit this remotely by manipulating the gblOrgID parameter to execute arbitrary SQL commands, potentially leading to unauthorized data access, modification, or deletion from the underlying database.

Technical details

A SQL injection vulnerability exists in the /tools/upgradeattribute.php file of Chanjet CRM up to version 20251106. The vulnerability is triggered through unsanitized input in the gblOrgID parameter, allowing an unauthenticated remote attacker to inject arbitrary SQL code. The attack is network-accessible with no apparent authentication or user interaction required. Successful exploitation grants an attacker the ability to read, modify, or delete database records, depending on database permissions. No patch from the vendor has been released despite early disclosure notification.

Affected products

  • Chanjet CRM up to 20251106

Timeline

  • 2025-11-30: disclosed
  • 2025-11-30: advisory

References

Related threats